Karbon achieves SOC 2 Type 1 certification
Keeping customer data safe and secure is a huge responsibility and a top priority for us at Karbon. Today, we are proud to announce that we are going one step further in our efforts to protect our customer’s data, having achieved SOC 2 Type 1 certification.
We embarked on this examination as part of our ongoing commitment to delivering the most robust, professional, and secure experience to our customers. The receipt of the SOC 2 Type 1 report comes after many months work and significant effort by the entire Karbon team.
Karbon — a service organization
System and Organization Controls (SOC) reports are designed to help companies that provide services to other organizations, service organizations, build trust and confidence in the services performed and controls related to these services through a report issued by an independent CPA. There are several types of SOC reports that can be issued by a CPA. The type of report needed by a service organization is determined by the management of the service organization and the needs of the users of the service. Karbon is a service organization, so it is important for us to obtain a SOC report for our services and the systems and internal control processes we have implemented to address risks associated with providing our services and the use of your data.
Our management team has determined that a SOC 2 report is the appropriate report to communicate the effectiveness of our security processes, our methods of addressing risk, and protecting your information.
What is SOC 2 Type 1 Report?
There are several types of SOC reports that can be issued by a CPA for a service organization. In short, a SOC 2 report speaks to the effectiveness of internal controls (i.e. internal business system and/or processes) relevant to the Security, Availability, Confidentiality, Processing Integrity, or Privacy of a service organization. Further, a SOC 2 report can be issued as either a Type 1 report or a Type 2 report.
A SOC 2 Type 1 report speaks to the design of our internal control processes; whereas, a SOC 2 Type 2 report speaks to design and operation of our internal control processes.
Our management team has determined that a SOC 2 Type 1 report for internal controls relevant to Security, Availability, and Confidentiality is an appropriate report to initially communicate our information security and risk management processes regarding the Karbon platform.
We have engaged an independent CPA firm to perform an examination of our internal control processes, and we have received a SOC 2 Type 1 from this CPA firm to demonstrate that we have implemented controls to address risk and protect the information we collect and use to provide our services, in accordance with the

:format(avif))

:format(jpeg))
:format(jpeg))
:format(jpeg))
:format(jpeg))