Sphere Blog
2 min

Sphere Achieves SOC 2 Type II Certification

Independent validation of Sphere’s security, availability, and compliance controls through SOC 2 Type II certification.

Written by
Sphere Team
Published on
September 14, 2026

Sphere has completed its second consecutive SOC 2 Type II audit, independently conducted by Insight Assurance and covering a review period that extended into 2026. The report validates that our security, availability, and confidentiality controls operated effectively throughout.

A first SOC 2 Type II report shows a company built the right controls. Each subsequent one shows they held up: new products, new markets, new partners, and a larger team all operating inside the same framework.

Why Consecutive Reports Matter

SOC 2 Type II evaluates how controls perform over an extended period rather than at a single point in time. Auditors test whether access reviews actually happen, whether incidents follow documented response procedures, and whether changes ship through controlled processes, month after month.

Controls that work for a company standing still often break when the company grows. Since our last audit, Sphere has shipped new products, scaled transaction activity, and added people and systems across the platform. This year's audit also assessed a broader scope of our operations than the first, and the framework held.

Scope of the Certification

The audit assessed the systems, processes, and controls supporting Sphere's platform and APIs across three trust services criteria:

  • Security
  • Availability
  • Confidentiality

This includes the production infrastructure that processes live customer transactions on Sphere's platform.

Compliance Is the Product

Sphere builds payment infrastructure for regulated finance. Our customers include institutions that answer to their own auditors, regulators, and risk committees, and they extend that scrutiny to every vendor in their stack. We hold our internal security posture to the same standard we build into the platform itself.

In practice, that looks like:

  • Access controls and monitoring across production systems
  • Secure development and change management practices
  • Continuous risk assessment and tested incident response procedures
  • Ongoing third-party and vendor risk management

What This Means for Customers and Partners

The SOC 2 Type II report gives compliance and procurement teams third-party evidence they can rely on during vendor due diligence, security reviews, and ongoing monitoring. Certification is a continuous exercise, and Sphere maintains a standing program of control monitoring, testing, and improvement so our security posture evolves alongside our platform and the regulatory landscape.

Customers and partners can request the full report through the Sphere team or visit our Trust Center for additional documentation, certifications, and security details.

Annual recertification is now standard practice at Sphere, alongside the ongoing work between audits that makes each report possible.

About the author

Sphere Team

Sphere Team

Insights and research

Subscribe to Sphere Blog

No spam. Just the latest releases and tips, interesting articles, and exclusive interviews in your inbox every week.

Construyamos el futuro de las finanzas, más rápido

Únase a las empresas que ya están creciendo con Sphere.

Empezar
Lea los documentos