SOC2C
Harvey logo

Harvey

harvey.ai· United States· 51–200 employees· Founded 2022
Trust level
Report Verified
Independently verified

The SOC2C verification team reviewed the company's uploaded SOC 2 report and cross-referenced the auditor against AICPA-registered CPA firms.

SOC 2 report confirmed; auditor Schellman cross-referenced Verified Jan 2026

Harvey is SOC 2 Type II compliant, audited by Schellman, with its most recent report dated Jan 2026. Harvey also holds ISO 27001, GDPR, and CCPA.

Framework
Auditor
Last report
Jan 2026
Renewal
Renews Jan 2027

About

Domain-specific AI for legal and professional services.

Compliance & infrastructure

Key controls
  • Encryption at rest
  • Encryption in transit
  • MFA / SSO enforced
  • Annual pen test
  • BCP / DR
Hosting
Microsoft AzureAWS

Penetration test

Unknown. Harvey's penetration test vendor isn't listed yet.

Ask Harvey to add who performed their pen test:

Complete this profile

9/11 details · 82%

SOC2C shows the verified essentials. 2 details are not yet provided. Trust centers list more, so we invite the owner to fill the gaps here.

  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Subprocessors
    List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.

Frequently asked

Is Harvey SOC 2 compliant?
Harvey is SOC 2 Type II compliant, audited by Schellman, with its most recent report dated Jan 2026. On SOC2C this listing is Report Verified.
Who audited Harvey?
Schellman, an AICPA-registered CPA firm.
When does Harvey's SOC 2 renew?
Harvey's SOC 2 is due to renew in Jan 2027.
Is Harvey ISO 27001 certified?
According to Harvey's public trust center, Harvey is ISO 27001 certified. On SOC2C this listing is Report Verified.
Is Harvey GDPR compliant?
According to Harvey's public trust center, Harvey is GDPR compliant. On SOC2C this listing is Report Verified.

AI peers that completed SOC 2