Vantage is now SOC 1 Type 2 Compliant

by Vantage Team


Vantage Enhances Access Controls for Managed Service Providers

Today, we’re excited to share that Vantage is now SOC 1 Type 2 compliant. This milestone underscores our ongoing commitment to earning and maintaining the trust of our customers - particularly those in regulated industries that rely on Vantage to help manage and understand their cloud costs.

Many of our customers use Vantage as a financial system of record for FinOps or cloud cost management. For teams in finance, engineering, and procurement, having confidence that the data Vantage surfaces is consistent, secure, and auditable isn’t a nice-to-have - it’s critical. Our SOC 1 Type 2 report provides independent validation that our internal controls meet a high bar for both design and ongoing performance. This isn’t the first SOC certification announcement from Vantage either: Since 2023, we’ve been SOC 2 Type 2 compliant which represents that our security and privacy policies are compliant with the standards established by the American Institute of Certified Public Accountants (AICPA).

This certification is especially relevant for customers who:

  • Integrate Vantage data into broader FP&A processes
  • Use Vantage outputs to inform accruals, allocations, and budgeting
  • Rely on our platform during financial audits or SOX compliance reviews
  • Invoice their end-clients based upon the data available in the platform through our Managed Service Provider offering.

The audit was conducted by an independent third party and covers a multi-month review period. It included a detailed examination of Vantage’s internal control environment, including processes related to data integrity, system access, change management, and more. As with our existing SOC 2 Type 2 report, this process represents a deep collaboration across our engineering, security, and operations teams.

You can request a copy of our SOC 1 Type 2 report by reaching out to security@vantage.sh or through your Vantage customer success representative. We continue to invest in our security and compliance posture, with additional certifications in progress to support customers operating in regulated and enterprise environments. To learn more, head to our security page or security documentation.

Frequently Asked Questions

1. What is being announced today

Vantage has been certified as being SOC 1 Type 2 compliant in accordance with the standards of the American Institute of Certified Public Accountants (AICPA).

2. Who is the customer?

Customers who use Vantage data for financial reporting, internal controls, or must comply with regulatory frameworks, such as SOX.

3. How much does this cost?

There is no cost to the customer.

4. What is SOC 1 Type 2 Certification and how is it different from SOC 2?

The SOC 1 Type 2 certification focuses on controls relevant to customers’ financial reporting, while SOC 2 evaluates controls related to security, availability, and privacy. Both are based on AICPA standards. SOC 1 is often required by companies subject to SOX compliance.

5. Why does this matter?

If your auditors require evidence of controls from third-party vendors, the SOC 1 Type 2 report from Vantage provides that assurance. It reduces the need for extensive vendor due diligence or custom questionnaires.

6. How does this impact the SOC 2 Type 2 certification that Vantage already maintains?

There is no impact to Vantage’s existing SOC 2 Type 2 certification. Vantage will maintain both certifications for customers’ security and auditing.

7. How do I request a copy of Vantage’s SOC 1 Type 2 Report?

Please reach out to security@vantage.sh or your Vantage Customer Success representative to request a copy of the SOC 1 Type 2 report from Vantage.