SOC 2 Compliance

ORDR is
SOC 2 Type II
Certified.

An independent third-party auditor has verified that ORDR's security controls for the Security, Availability, and Confidentiality Trust Service Criteria operated effectively over a continuous 12-month audit period.

Type II
Continuous controls testing, not point-in-time
3 TSCs
Security, Availability, and Confidentiality in scope
Annual
Recertified every year to maintain compliance
What It Means

What SOC 2 Type II Means for Your Organization

Independent Verification

The SOC 2 Type II audit is conducted by an independent third-party auditor — not ORDR — who tests whether our described controls actually operated effectively over a continuous period.

Continuous, Not Point-in-Time

Unlike a Type I audit that assesses control design at a single point in time, a Type II audit tests control effectiveness over a sustained period, providing stronger assurance that controls are consistently applied.

Relevant to Your Vendor Risk Program

Many enterprise security programs require SOC 2 Type II reports as part of vendor assessment. ORDR's certification satisfies this requirement, and the full report is available to customers and prospects under NDA.

Ongoing Commitment

SOC 2 Type II certification is not a one-time achievement — it requires annual audits and continuous control maintenance. ORDR undergoes annual recertification to maintain its certification.

Audit Scope

Trust Service Criteria in Scope

Security

The system is protected against unauthorized access, use, or modification.

Multi-factor authentication on all production system access
Role-based access control with least-privilege enforcement
Continuous monitoring and anomaly detection
Encryption in transit (TLS 1.2+) and at rest (AES-256)
Regular penetration testing by independent third parties

Availability

The system is available for operation and use as committed or agreed upon.

Hosted on redundant cloud infrastructure (AWS)
Defined SLAs for platform availability
Business continuity and disaster recovery plans tested regularly
Incident response procedures with defined escalation and communication protocols

Confidentiality

Information designated as confidential is protected as committed or agreed upon.

Customer data segregation in multi-tenant environments
Confidential data handling procedures for personnel
Non-disclosure agreements for all personnel with data access
Secure data destruction at contract termination
Audit Details

Scope and Coverage

Platform ScopeORDR's SaaS platform, including device discovery, behavioral analysis, risk assessment, and policy enforcement capabilities
Infrastructure ScopeProduction cloud infrastructure hosted on Amazon Web Services (AWS) in the United States (us-east-1)
Audit PeriodThe most recent audit covered a continuous 12-month period, providing evidence of sustained control effectiveness
AuditorConducted by an independent, PCAOB-registered third-party accounting firm
Report TypeType II — tests control effectiveness over the audit period, not just point-in-time design (Type I)
Common Questions

SOC 2 FAQ

Can I get a copy of the SOC 2 Type II report?

Yes. The full SOC 2 Type II report is available to current customers and qualified prospects under a mutual NDA. Contact your account team or security@ordr.net to request a copy.

Which Trust Service Criteria does the audit cover?

The ORDR SOC 2 audit covers the Security, Availability, and Confidentiality Trust Service Criteria. These were selected as the criteria most relevant to ORDR's operational and data handling practices.

How recent is the certification?

ORDR undergoes annual SOC 2 Type II audits. Contact your account team for information on the current certification period.

Does ORDR have other security certifications?

In addition to SOC 2 Type II, ORDR complies with GDPR and CCPA requirements. We are evaluating ISO 27001 certification as part of our ongoing compliance roadmap. See our Trust Center for the most current information.

Does ORDR have a vulnerability disclosure program?

Yes. Security researchers who identify vulnerabilities in ORDR's platform can submit findings to security@ordr.net. We commit to acknowledging reports within 48 hours and providing an initial assessment within 10 business days.

Request the
Full Audit Report

The complete SOC 2 Type II report is available to current customers and qualified prospects under a mutual NDA.