SOC2C

Is this your company? Buyers are checking intigriti here. Claim intigriti.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
intigriti logo

intigriti

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

intigriti is SOC 2 Type II compliant. intigriti also holds ISO 27001, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Intigriti offers bug bounty and agile penetration testing solutions powered by Europe's #1 leading network of ethical hackers. This report is a live dashboard of our current security & compliance posture, which we publish publicly. Feature here is an overview of our cybersecurity documentation, practices, certifications, compliance documents and Frequently Asked Questions. We are ISO 27001:2013, SOC2 Level 2 certified and classified as a NIS2 Important entity. Also make sure to check out [our very own bug bounty program](https://app.intigriti.com/programs/intigriti/intigriti/detail)!

Compliance & infrastructure

Hosting
AWSGCP

Documents

2

Subprocessors

6
  • A
    Amazon Web Services · Cloud Hosting Provider (PaaS)
    Western Europe
  • G
    Google Cloud Platform · Cloud Hosting Provider (PaaS)
    Western Europe
  • M
    MongoDB, Inc. · Database Solution Provider (DBaaS)
    Western Europe
  • I
    Intigriti LTD · Payroll Subsidiary
    United Kingdom
  • I
    Intigriti EMEA bv · Intigriti group entity
    Belgium
  • I
    Intigriti NV · Intigriti group entity
    Beligum

Compliance leadership

The person who leads intigriti's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. intigriti's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

2026 ISO 27001:2022 surveillance audit completedJun 2026

Our latest ISO 27001:2022 surveillance audit has concluded with no Major or Minor non-conformities, and the continuation of our current ISO 27001:2022 certification from our ANAB accredited certification body, ISOQAR. Access to the relevant Statement of Applicability (v3, dated 23/04/2025) can be requested via the Trust Center.

Latest SOC2 Type 2 audit report publishedApr 2026

We've updated our SOC2 Type 2 report with the most recent version covering the audit period of March 2025 - March 2026. No exceptions were noted.

ISO 27001 2022 certificate updatedJun 2025

We've updated to our new ISO 27001 certificate. This is for the latest 2022 standard and now also includes our head offices.

SOC2 certificate updatedMay 2025

We replaced our SOC2 Level 2 certificate with the most recent one for audit period March 2024 - March 2025. No non-conformities were detected.

Updated Security PoliciesMay 2025

We've updated our policy packet on the trust center to our latest version of all security policies. This includes changes we've had to apply to comply to the new ISO 27001:2022 standard.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is intigriti SOC 2 compliant?
intigriti is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is intigriti ISO 27001 certified?
According to intigriti's public trust center, intigriti is ISO 27001 certified. On SOC2C this listing is Listed.
Is intigriti GDPR compliant?
According to intigriti's public trust center, intigriti is GDPR compliant. On SOC2C this listing is Listed.
Is intigriti SOC 2 Type I or Type II?
intigriti is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use intigriti's SOC 2 for a vendor risk assessment?
Yes. intigriti's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by intigriti

Reproduced from intigriti's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Are you externally audited yourself?
Strong yes! We run multiple bug bounty programs (public & private) to ensure the cybersecurity posture of our platform and infrastructure. Additionally, we run various tools which execute automated checks on our cloud infrastructure on configuration and behavior with a reference to SOC2, ISO 27001, security recommendations from vendors and the CIS benchmarks. From a compliance perspective, we are recurrently audited as per the ISO 27001 surveillance audit and SOC2 Level 2 requirements. If you have specific concerns, please reach out to us so we can discuss.
Where and how is my data stored securely?
We host our infrastructure solely in EU regions. In the application itself your data is processed in a memory safe programming language using strong authorization checks which are security tested upon changes. The data itself is encrypted via AES/256/GCM with a strong cryptographic key specific to that customer which is rotated every 30 days. The customer keys are then encrypted by our own root keys which are rotated every 6 months. Before storing the data at cloud provider, it is encrypted for a second time to ensure full encryption at rest.
Do you have a Secure Software Development Lifecycle Policy (SDLC)?
Yes! We map our own (S)SDLC to the OWASP SAMM framework to ensure best practices are tracked and applied. For development, we utilize the OWASP ASVS. Any significant change first goes for approval through one of our architectural and scoping meetings to define acceptance criteria. Afterwards, a risk assessment is performed to add security requirements. This is all tracked in a ticket flow, triaged, and tracked accordingly to the correct release schedule. Any development follows a clear framework that alleviates the developers from most security coding concerns. Their Integrated Development Environment (IDE) performs security checks such as static code analysis (SAST). Our pipeline also performs additional checks which will fail the build. If development work is ready, a pull request needs to be opened which is then reviewed by a senior developer before being able to be merged. If the change is implemented, internal security testing is performed according to the WSTG and a final security review is performed. Should the security review find bug tickets opened without risk acceptance, the release is postponed until a decision has been made. After the release, we depend on our public and private bug bounty programs. Any security findings are fed back into our development cycle in the form of process changes, framework modifications, or additional awareness content.
Are your employees vetted?
Yes! All employees go through a criminal and background check by a reputable third party during the hiring process. Additionally, we look at the previous experience of the candidate, and perform a rigorous culture and technical interview to ensure the person is a correct fit. Employees also need to sign a mutual non-disclosure that makes them legally liable if they were to leak information or perform misconduct.
Can Intigriti assist with NIS2, ISO 27001, SOC2, DORA and others?
Yes! We help you achieve compliance with these regulations in several ways. Firstly, our Vulnerability Disclosure Programs are perfect for third party risk management and monitoring. Our Managed Bug Bounty and Pen-testing-as-a-Service engagements help with resilience testing. Finally, all three products can be used for vulnerability identification and information sharing. For all of these, we generate on-demand reports, attestations, and executive summaries using rich reporting and analytics so organizations can have adequate compliance and risk reporting. We fulfill the appropriate controls under the following standards; ISO 27001:2022 controls: - 5.7 Threat Intelligence - 5.35 Independent Review of Information Security - 8.8 Management of Technical Vulnerabilities ISO 27001:2013 controls: - A.14.2.8: Testing of security functionality shall be carried out during development. (Technical) SOC2 controls: - CC 3.4 Risk management program established - CC 4.1 Control self-assessments conducted - CC 7.2 Vulnerabilities scanned and remediated - CC 7.2 Penetration testing performed - CC 8.1 Vulnerabilities scanned and remediated - CC 8.1 Penetration testing performed NIS2 directives: - Risk Management (art. 21)​ - Incident handling and Reporting (art. 23)​ - Supply Chain Security (art. 18)​ - Vulnerability Disclosure (VDP) (art. 30)​ - Supervision and Enforcement (art. 33)​ - Cybersecurity culture and awareness (art. 18, 21)

Media & Entertainment peers that completed SOC 2