SOC-2

Our current SOC-2 posture and how to request the report.

Status: SOC-2 Type II audit in progress

We are partnered with an external auditor and the Type II observation window is underway, covering security, availability, and confidentiality. Until the report is issued, we share our current security overview, controls inventory, gap analysis, and the expected completion timeline under NDA on request — see the sub-processors list for the infrastructure in scope.

Trust principles covered

Privacy and Processing Integrity are not in scope for the initial Type II window. We will expand scope as customer contracts require.

How to request the report

  1. Email security@ovriven.com with your company name and the email of the security reviewer.
  2. We send back a mutual NDA. Most customers can co-sign one off the shelf within an hour.
  3. Once signed, we share the latest report (and the bridge letter, when applicable) along with the SIG / CAIQ questionnaire response.

Adjacent compliance

Last updated: 2026-05-06.