SOC2C

Is this your company? Buyers are checking Capital on Tap here. Claim capitalontap.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Capital on Tap logo

Capital on Tap

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Capital on Tap is SOC 2 Type II compliant. Capital on Tap also holds ISO 27001.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

At Capital on Tap, security is a core value that underpins everything we do. We recognise the importance of safeguarding our customers’ data and maintaining their trust. We are proud to hold both ISO 27001 certification and SOC 2 Type 2 attestation, clear indicators of our commitment to maintaining rigorous security, availability, and confidentiality standards.

Compliance & infrastructure

Hosting
Azure

Documents

3

Subprocessors

11
  • M
    Microsoft Azure · Cloud provider
  • G
    Google Workspace · Identity provider
  • C
    Cloudflare · Cloud monitoring
  • D
    Datadog · Cloud monitoring
  • J
    Jira · Collaboration
  • H
    HubSpot · Marketing
  • F
    Fivetran · Data storage and processing
  • S
    Slack · Collaboration
  • V
    Vanta · Security
  • S
    Snowflake · Data storage and processing
  • B
    Bob · Employee management

Compliance leadership

The person who leads Capital on Tap's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Capital on Tap's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

ISO/IEC 27001:2022 — First Surveillance Audit PassedJun 2026

We have completed our first annual surveillance audit against ISO/IEC 27001:2022. Our certification remains valid, and the updated certificate and surveillance audit report are now available here, replacing the 2025 versions.

ISO 27001Nov 2025

We have recently updated our ISO 27001 certification. The revised document is now available in our Trust Center.

SOC 2 Type 2Apr 2025

Capital on Tap has successfully achieved SOC 2 Type 2 attestation for the second consecutive year, this time expanding our coverage to include all five Trust Services Criteria: Security, Availability, Confidentiality, Processing Integrity, and Privacy. This milestone demonstrates the maturity and effectiveness of our internal controls across every aspect of our operations, further reinforcing our commitment to safeguarding customer data and delivering reliable, trustworthy services. Achieving and maintaining SOC 2 Type 2 across all five pillars reflects not only our strong security posture but also our dedication to transparency, operational excellence, and continuous improvement. It’s a significant step in ensuring our customers and partners can continue to place their trust in Capital on Tap.

ISO 27001Apr 2025

Capital on Tap has successfully achieved ISO 27001 certification, demonstrating its ongoing commitment to the highest standards of information security. This internationally recognised accreditation validates the company’s implementation of a robust Information Security Management System (ISMS), designed to protect customer data, manage risks effectively, and ensure operational resilience. The certification reflects Capital on Tap’s dedication to maintaining trust with its customers and partners by embedding security best practices across its people, processes, and technologies. It also supports the company’s growth ambitions by reinforcing regulatory compliance and strengthening its position as a trusted provider in the fintech space.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Capital on Tap SOC 2 compliant?
Capital on Tap is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Capital on Tap ISO 27001 certified?
According to Capital on Tap's public trust center, Capital on Tap is ISO 27001 certified. On SOC2C this listing is Listed.
Is Capital on Tap SOC 2 Type I or Type II?
Capital on Tap is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Capital on Tap's SOC 2 for a vendor risk assessment?
Yes. Capital on Tap's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Capital on Tap penetration tested?
Capital on Tap hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.