Is Atarim SOC 2 Compliant?
Yes — SOC 2 Type 2, with controls independently audited and verified to work over time rather than self-declared.
Security matters when you’re collaborating on live websites and handling client feedback. Atarim is SOC 2 Type 2 compliant — its security controls have been independently audited and verified to operate effectively over time, which helps agencies, enterprise teams and internal departments meet their own compliance requirements.
Independently audited controls, not self-attested claims.
Security matters when you’re collaborating on live websites and handling client feedback. Atarim is SOC 2 Type 2 compliant — its security controls have been independently audited and verified to operate effectively over time, which helps agencies, enterprise teams and internal departments meet their own compliance requirements.
What SOC 2 Is
SOC 2 (System and Organization Controls 2) is a compliance framework developed by the American Institute of Certified Public Accountants (AICPA). It evaluates how an organisation protects customer data and maintains secure systems, measured against defined Trust Services Criteria.
Reports come in two types, and the difference matters when you’re assessing a vendor.
| Type | What it evaluates | Assessed |
|---|---|---|
| SOC 2 Type 1 | The design of security controls. | At a single point in time. |
| SOC 2 Type 2 — Atarim’s status | Both the design and the operating effectiveness of controls. | Over an extended audit period. |
What’s in Atarim’s Scope
The audit is scoped to the Security Trust Services Category, and covers controls in these areas.
| Control area | What it covers |
|---|---|
| Role-based access controls | Who can reach what, based on their role. |
| Multi-factor authentication | An additional verification step at sign-in. |
| Encryption | Data protected both at rest and in transit. |
| Secure cloud infrastructure | How the underlying platform is configured and protected. |
| Monitoring, logging and alerting | Visibility of what’s happening across the system. |
| Incident detection and response | How issues are identified and handled. |
| Vulnerability management and penetration testing | Finding and closing weaknesses proactively. |
| Change and deployment management | How changes reach production safely. |
What This Means for You
| Benefit | In practice |
|---|---|
| Verified security practices | Controls have been independently audited rather than self-attested. |
| Enterprise-ready platform | Built to meet the expectations of agencies and larger organisations. |
| Simpler procurement | Type 2 status speeds up vendor reviews and security assessments. |
| Transparency | The attestation report is available to eligible customers on request. |
Requesting the Attestation Report
- Contact Atarim support and ask for the SOC 2 Type 2 attestation report. All paying customers are eligible to request it.
- Sign a non-disclosure agreement if one is requested. Whether an NDA is needed depends on the context of the request.
Doing Your Part
SOC 2 covers how Atarim protects your data. How your own workspace is configured is up to you, and two of the audited control areas have direct equivalents you can act on.
FAQs
Is Atarim SOC 2 compliant?
Yes — SOC 2 Type 2, meaning controls were independently audited for both design and operating effectiveness over an extended period.
Who can request the attestation report?
All paying Atarim customers are eligible to request it.
Is an NDA required?
Possibly. Atarim may request a non-disclosure agreement before sharing the report, depending on the context of the request.
Which Trust Services Category is covered?
The audit is scoped to the Security category.
What’s the difference between Type 1 and Type 2?
Type 1 assesses the design of controls at a single moment. Type 2 assesses design and whether the controls actually operated effectively over a period of time.
Does this cover how my own workspace is set up?
No. SOC 2 covers Atarim’s controls. Your permissions, access reviews and whether your team uses two-factor authentication remain yours to manage.
Where do I ask for the report?
Through Atarim support, using live chat in the dashboard or by email.
Conclusion
Atarim’s SOC 2 Type 2 compliance means its security controls have been independently validated as working, not merely declared. For teams that need to demonstrate their tooling meets a standard, that’s the evidence procurement and vendor risk reviews usually ask for.
Request the report early, and pair it with sensible configuration at your end — two-factor authentication, least-privilege roles, and regular access reviews. Discover Managing Team Members & Collaborators
Tips & best practices
- Request the SOC 2 report early during onboarding or procurement reviews.
- Allow time for an NDA, in case one is required.
- Use role-based permissions to enforce least-privilege access.
- Enable two-factor authentication for every team member.
- Review user access regularly as part of your own security process.