Entropia achieves SOC 2 Type II certification. What it means for the security of our dataroom.
Many providers will claim that your data is safe with them, but how do you know?
At Entropia, we didn’t want customers to take our word for it alone. That’s why we went through months of independent, rigorous auditing to achieve SOC 2 Type II attestation.
"SOC" stands for System and Organisation Controls. It is an audit framework designed by the American Institute of Certified Public Accountants (AICPA).
The "2" distinguishes it from other SOC reports:
Despite its origins in accountancy, SOC2 has become one of the most widely recognised standards for technology companies that store or process sensitive customer data. The framework evaluates an organisation across five “Trust Services Criteria”:
And there are two levels of assurance:
For customers, that distinction is crucial. Type II requires months of continuous evidence, not just documents. It’s a discipline, not a checkbox.
Achieving SOC2 Type II standards required implementing and documenting controls that span every part of our organisation:
Security isn’t a side project. It’s in every code commit, every access request, every system change.
And crucially, we have been independently audited over several months to prove that these controls are enforced in practice, not just documented in theory.
For customers, SOC2 Type II provides third-party assurance. It shows that security at Entropia is not simply promised but independently verified. It is among the most widely recognised and demanding attestations available to software-as-a-service providers, requiring stringent controls that operate consistently over time.
This means your data is handled responsibly, systems are monitored, and risks are actively managed. At the same time, it reflects structured, disciplined engineering practices: formal access reviews, reproducible build processes, and operational logs that withstand scrutiny.
It didn’t make us secure. It made us prove it.
We are not the only ones involved in protecting your data. When you use Entropia, your data is processed through our systems, but when it is stored at rest, it lives on the infrastructure of a cloud provider.
Among our subprocessors, this cloud provider is the most important one: it physically hosts your data. That’s why, when evaluating the security of any SaaS provider, it’s essential to also consider the security standards of the cloud providers they rely on.
Our hosting partner, Scaleway, is certified under ISO/IEC 27001, the internationally recognised standard for information security management systems. This certification applies to Scaleway’s infrastructure and demonstrates that their data centres and cloud environment are governed by strong security and risk management practices.
For Entropia’s customers, this provides an additional layer of assurance: while our SOC2 Type II attestation validates the way we manage and operate our own controls over time, Scaleway’s ISO 27001 certification confirms that the underlying infrastructure on which our services run is also independently verified to follow best practices.
Together, these frameworks address different layers of security: from our operational processes to the physical and cloud environment that supports them.
SOC2 Type II is one of the most widely recognised and rigorous security attestations for SaaS providers, and we are proud to meet it. But for us it is only the floor, not the ceiling.
We are adopting a Zero Trust security model on top: an approach in which no device, user, or request is trusted by default. Every action is authenticated, authorised, and monitored continuously. This model goes beyond the requirements of SOC 2 and strengthens resilience at the architectural level.
💡 Read more: Our zero-trust security model →