SOC2C

Is this your company? Buyers are checking Holistiplan here. Claim holistiplan.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Holistiplan logo

Holistiplan

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Holistiplan is SOC 2 Type II compliant. Holistiplan also holds CCPA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Holistiplan is an award-winning software for financial planners and investment advisors built to systematize and automate the process of reviewing a client’s financial documents to find potential planning opportunities. Holistiplan uses optical character recognition (OCR) to read uploaded documents and generate client-ready reports that uncover potential financial planning opportunities through an algorithmic program. Financial professionals can then run various scenarios to determine future outcomes.

Compliance & infrastructure

Hosting
AWS
Data handled
Customer personally identifiable information

Documents

15

Subprocessors

1
  • A
    Amazon Web Services · Cloud Hosting
    U.S. East-1, Virginia

Compliance leadership

The person who leads Holistiplan's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Holistiplan's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Holistiplan SOC 2 compliant?
Holistiplan is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Holistiplan CCPA compliant?
According to Holistiplan's public trust center, Holistiplan is CCPA compliant. On SOC2C this listing is Listed.
Is Holistiplan SOC 2 Type I or Type II?
Holistiplan is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Holistiplan's SOC 2 for a vendor risk assessment?
Yes. Holistiplan's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Holistiplan penetration tested?
Holistiplan hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by Holistiplan

Reproduced from Holistiplan's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Does Holistiplan provide cloud service(s)?
Yes, Holistiplan’s tax software is completely cloud-based. Our solution is offered as a SaaS tool and leverages industry-leading technology through our partnership with Amazon Web Services (AWS). While our service is multi-tenant, AWS leverages tenant isolation so that our data is kept entirely separate and is not accessible to anyone outside of the Holistiplan organization.
Does Holistiplan encrypt our data?
Yes, Holistiplan encrypts all data within our application both at rest and in transit. We leverage industry-leading 256 bit encryption.
Does Holistiplan have a dedicated person or group responsible for privacy compliance?
Yes, Holistiplan’s CTO works in conjunction with the CISO to maintain our compliance and security standards as they relate to data privacy.
Does Holistiplan have an internal compliance and/or ethics program?
Yes. Holistiplan’s Security Program is informed by SOC 2 Type II and NIST frameworks, and is continuously monitored for control effectiveness using a number of technical tools and processes. Conduct and ethics are covered within this security and compliance program.
Does Holistiplan maintain policies and procedures to enable compliance with legal, regulatory, statutory, or contractual obligations regarding information security requirements?
Yes, Holistiplan has extensive documented policies and procedures in place that are designed to support SOC 2 Type II compliance. Holistiplan monitors for compliance and undergoes annual SOC 2 audits.

Business & Industrial peers that completed SOC 2