July 01, 2024




Raising the bar Tartan achieves SOC2 data security compliance

What is SOC2?

SOC2 is a set of guidelines that helps companies prove they're adhering to best practices in security and privacy. It covers things like:

The way you manage your data, including how you store it, who has access to it, and what steps you take to ensure that data isn't leaked or stolen.

How well trained your employees are on security protocols (this includes both technical training and awareness).

The steps taken by management when something goes wrong with those protocols--for example, if someone accidentally sends out an email containing sensitive information without first encrypting it.

Why SOC2 Matters for Tartan

SOC2 compliance is essential for Tartan because it helps us to keep customer data safe and secure.

The SOC2 report is a comprehensive review of our internal controls, policies, and procedures that ensure the confidentiality, integrity, and availability of your information. It also measures how well we protect against fraud or theft by outsiders.

What Tartan Does to Achieve SOC2 Compliance

Tartan does everything it can to protect your data. All of our security protocols are SOC2 compliant, including:

  • Encryption - We encrypt all data at rest and in transit so that only authorised users can access it.

  • Data storage and transmission - We store your information on secure servers with limited access privileges, and we use secure connections when transmitting sensitive information over public networks like the Internet or mobile networks (e.g., HTTPS).

Access control - You can choose whether or not to share some or all of your personal information with us; we will only use this information for the purpose(s) agreed upon by both parties when entering into our agreement with you (and only if there is no other legal basis for doing so).

The Benefits of SOC2 for Tartan Customers

As a Tartan customer, you will benefit from SOC2 certification in the following ways:

  • Improved security - The certification demonstrates that we have implemented and maintained appropriate measures to protect your data from unauthorised access, alteration, or destruction.

  • Better data protection - Customers can be confident that their information is being handled with care by an organisation that has been independently audited against stringent requirements set forth by the American Institute of Certified Public Accountants (AICPA).

  • Reliable services and support - With SOC2 compliance comes increased confidence in our ability to deliver reliable service at all times--whether it's during regular business hours or off-hours emergencies like natural disasters or cyber attacks on our systems. 

What to Look for in a SOC2-Compliant Provider

In order to ensure that your data is safe, look for a provider that has the following:

  • Security protocols in place to protect your data- This includes encryption and data storage and transmission security measures.

  • Access control procedures consistent with industry standards and best practices, such as multi-factor authentication or password managers.


The SOC2 report is a certification that guarantees that an organisation’s information security program is operating effectively. It provides assurance to customers, investors and other stakeholders that the company has implemented appropriate controls to protect their personal data.The SOC2 report is an important piece of your business's reputation as it demonstrates that you are committed to protecting customer data in accordance with industry standards and best practices.

