Help center
Open dashboard

Is Atarim SOC 2 Compliant?

Yes — SOC 2 Type 2, with controls independently audited and verified to work over time rather than self-declared.

Atarim team Updated 3 Aug 2026 · 4 min read
FAQs and Troubleshooting
Atarim security and compliance settings
Before you start

Relevant for

  • Agencies managing client websites, enterprise and internal teams, IT and security stakeholders, and procurement or vendor risk teams.

Required knowledge

  • None. This is written for technical and non-technical readers alike.

Tools & resources needed

  • A current Atarim subscription, which is required to request the attestation report.

Security matters when you’re collaborating on live websites and handling client feedback. Atarim is SOC 2 Type 2 compliant — its security controls have been independently audited and verified to operate effectively over time, which helps agencies, enterprise teams and internal departments meet their own compliance requirements.

Independently audited controls, not self-attested claims.

Security matters when you’re collaborating on live websites and handling client feedback. Atarim is SOC 2 Type 2 compliant — its security controls have been independently audited and verified to operate effectively over time, which helps agencies, enterprise teams and internal departments meet their own compliance requirements.

What SOC 2 Is

SOC 2 (System and Organization Controls 2) is a compliance framework developed by the American Institute of Certified Public Accountants (AICPA). It evaluates how an organisation protects customer data and maintains secure systems, measured against defined Trust Services Criteria.

Reports come in two types, and the difference matters when you’re assessing a vendor.

TypeWhat it evaluatesAssessed
SOC 2 Type 1The design of security controls.At a single point in time.
SOC 2 Type 2 — Atarim’s statusBoth the design and the operating effectiveness of controls.Over an extended audit period.
Type 2 is the stronger of the two
It confirms the controls are not just in place, but consistently working as intended across the whole audit period — which is what a vendor risk review is usually looking for.

What’s in Atarim’s Scope

The audit is scoped to the Security Trust Services Category, and covers controls in these areas.

Control areaWhat it covers
Role-based access controlsWho can reach what, based on their role.
Multi-factor authenticationAn additional verification step at sign-in.
EncryptionData protected both at rest and in transit.
Secure cloud infrastructureHow the underlying platform is configured and protected.
Monitoring, logging and alertingVisibility of what’s happening across the system.
Incident detection and responseHow issues are identified and handled.
Vulnerability management and penetration testingFinding and closing weaknesses proactively.
Change and deployment managementHow changes reach production safely.
Note
Every control listed was independently tested to confirm it operated effectively throughout the audit period — not simply that it existed on paper.

What This Means for You

BenefitIn practice
Verified security practicesControls have been independently audited rather than self-attested.
Enterprise-ready platformBuilt to meet the expectations of agencies and larger organisations.
Simpler procurementType 2 status speeds up vendor reviews and security assessments.
TransparencyThe attestation report is available to eligible customers on request.

Requesting the Attestation Report

  1. Contact Atarim support and ask for the SOC 2 Type 2 attestation report. All paying customers are eligible to request it.
  2. Sign a non-disclosure agreement if one is requested. Whether an NDA is needed depends on the context of the request.
Request the report early
During onboarding or at the start of a procurement review, not when the security questionnaire is already overdue. Building in time for the NDA step avoids the report becoming the thing holding up a deal. Learn More About Getting Help And Support

Doing Your Part

SOC 2 covers how Atarim protects your data. How your own workspace is configured is up to you, and two of the audited control areas have direct equivalents you can act on.

Recommendation
Enable two-factor authentication for everyone on your team, and use role-based permissions to give people the least access they need to do their work. A vendor’s certification does not compensate for an over-permissioned workspace — the two work together. Explore Two-Factor Authentication
Review access as a habit, not a one-off
Agencies accumulate collaborators, contractors and former team members over time, and stale access is the most common gap in an otherwise well-run workspace. Discover User Roles And Permissions

FAQs

Is Atarim SOC 2 compliant?

Yes — SOC 2 Type 2, meaning controls were independently audited for both design and operating effectiveness over an extended period.

Who can request the attestation report?

All paying Atarim customers are eligible to request it.

Is an NDA required?

Possibly. Atarim may request a non-disclosure agreement before sharing the report, depending on the context of the request.

Which Trust Services Category is covered?

The audit is scoped to the Security category.

What’s the difference between Type 1 and Type 2?

Type 1 assesses the design of controls at a single moment. Type 2 assesses design and whether the controls actually operated effectively over a period of time.

Does this cover how my own workspace is set up?

No. SOC 2 covers Atarim’s controls. Your permissions, access reviews and whether your team uses two-factor authentication remain yours to manage.

Where do I ask for the report?

Through Atarim support, using live chat in the dashboard or by email.

Conclusion

Atarim’s SOC 2 Type 2 compliance means its security controls have been independently validated as working, not merely declared. For teams that need to demonstrate their tooling meets a standard, that’s the evidence procurement and vendor risk reviews usually ask for.

Request the report early, and pair it with sensible configuration at your end — two-factor authentication, least-privilege roles, and regular access reviews. Discover Managing Team Members & Collaborators

Tips & best practices

  • Request the SOC 2 report early during onboarding or procurement reviews.
  • Allow time for an NDA, in case one is required.
  • Use role-based permissions to enforce least-privilege access.
  • Enable two-factor authentication for every team member.
  • Review user access regularly as part of your own security process.

Related articles