
Harvey
Trust level
Report Verified
Independently verified
Listed
Domain
Report
Live
The SOC2C verification team reviewed the company's uploaded SOC 2 report and cross-referenced the auditor against AICPA-registered CPA firms.
SOC 2 report confirmed; auditor Schellman cross-referenced● Verified Jan 2026
Harvey is SOC 2 Type II compliant, audited by Schellman, with its most recent report dated Jan 2026. Harvey also holds ISO 27001, GDPR, and CCPA.
About
Domain-specific AI for legal and professional services.
Compliance & infrastructure
Key controls
- ✓Encryption at rest
- ✓Encryption in transit
- ✓MFA / SSO enforced
- ✓Annual pen test
- ✓BCP / DR
Hosting
Microsoft AzureAWS
Penetration test
Unknown. Harvey's penetration test vendor isn't listed yet.
Complete this profile
9/11 details · 82%SOC2C shows the verified essentials. 2 details are not yet provided. Trust centers list more, so we invite the owner to fill the gaps here.
- DocumentsList the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
- SubprocessorsList your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
Frequently asked
Is Harvey SOC 2 compliant?
Harvey is SOC 2 Type II compliant, audited by Schellman, with its most recent report dated Jan 2026. On SOC2C this listing is Report Verified.
Who audited Harvey?
Schellman, an AICPA-registered CPA firm.
When does Harvey's SOC 2 renew?
Harvey's SOC 2 is due to renew in Jan 2027.
Is Harvey ISO 27001 certified?
According to Harvey's public trust center, Harvey is ISO 27001 certified. On SOC2C this listing is Report Verified.
Is Harvey GDPR compliant?
According to Harvey's public trust center, Harvey is GDPR compliant. On SOC2C this listing is Report Verified.
Is Harvey CCPA compliant?
According to Harvey's public trust center, Harvey is CCPA compliant. On SOC2C this listing is Report Verified.
Is Harvey SOC 2 Type I or Type II?
Harvey is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Who audited Harvey's SOC 2?
Harvey's SOC 2 was audited by Schellman, an AICPA-registered CPA firm. SOC2C cross-references the auditor before a listing earns the Report Verified badge.
Can I use Harvey's SOC 2 for a vendor risk assessment?
Yes. Harvey's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Harvey penetration tested?
Yes — Harvey undergoes third-party penetration testing as part of its security program. The pentest vendor is listed on its SOC2C profile.
Is Harvey secure?
Security isn't a single yes/no, but Harvey is SOC 2 Type II compliant and holds SOC 2 Type II, ISO 27001, GDPR, CCPA, and undergoes third-party penetration testing. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Harvey have a bug bounty or vulnerability disclosure program?
Harvey hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@harvey.ai or via a /security page.
Who are Harvey's subprocessors?
Harvey's subprocessors aren't listed on SOC2C yet. The company can add them so buyers can assess fourth-party risk.
Where does Harvey host or store data?
Harvey hosts on Microsoft Azure, AWS. Data residency details are on its trust center.
Does Harvey encrypt data?
Yes — Harvey encrypts data at rest and in transit, per its trust center.
Does Harvey enforce MFA or SSO?
Yes — Harvey enforces multi-factor authentication / single sign-on, per its security controls.
Where is Harvey's trust center or security page?
Harvey's trust center is at https://trust.harvey.ai/. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
