SOC2C

Is this your company? Buyers are checking Netchex here. Claim netchex.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Netchex logo

Netchex

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Netchex is SOC 2 compliant.

Framework
SOC 2
Auditor
Last report
Renewal
View official trust center ↗

About

This page overviews Netchex's security program and is your one-stop shop for all your due diligence and vendor management needs. At Netchex, we understand that data confidentiality, integrity, and availability are paramount to your business's success and continued growth. That is why we bake our Information Security Team's commitment to data security into every aspect of our services. Call us at (877) 729-2661 or email at [hello@netchexonline.com](mailto:hello@netchexonline.com) for more information on how to protect your employee data by choosing Netchex.

Compliance & infrastructure

Hosting
Azure
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Subprocessors

1
  • M
    Microsoft Azure · Cloud provider

Compliance leadership

The person who leads Netchex's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Netchex's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Action Required: Critical Security Update for Apple UsersFeb 2026

A high-priority vulnerability is currently impacting Apple devices (iPhone, iPad, Mac, Apple Watch, Apple TV, and Apple Vision). While Netchex has not been impacted, we are sharing this information so you can take immediate steps to protect your organization and your employees. ### Immediate Actions 1. Update All Hardware: Ensure every Apple device (work and personal) is updated to the latest software version released after February 11, 2026. 2. Audit Connected Devices (on iPhone/iPad): - Text Message Forwarding: Go to Settings > Messages > Text Message Forwarding. Disable any unrecognized devices immediately. - Linked Devices: Go to Settings > \[Your Name]. Scroll to the bottom to review all signed-in devices. Remove any hardware you do not recognize. 3. Audit via iCloud.com (Web): - Log in to icloud.com/find. - Click All Devices at the top of the screen. - Review the list and select Remove from Account for any unrecognized or old hardware. ### Securing Your Netchex Account Our team is actively monitoring for unusual activity and will contact any impacted users directly. We strongly recommend you take these proactive steps within your Netchex account: - Turn on Multi-Factor Authentication (MFA): Navigate to Account Management -> Multi-Factor Authentication to add a vital extra layer of security. - Review your Master Audit Report: Go to Reports -> Audit to check for any…

Welcome to the New Netchex Trust CenterDec 2025

We are pleased to introduce this upgraded portal, replacing our previous site at security.netchex.com. This transition was designed to streamline your experience, making it easier to find our certifications and compliance data. New Feature: AI-Powered Q&A This portal now supports AI chat functionality. You can use the chat interface to ask questions directly about our security controls or specific details contained within our documents, getting you the answers you need faster than ever. Please remember to update your bookmarks to trust.netchex.com.

Netchex Not Impacted by Shai-Hulud Supply Chain AttackDec 2025

Hi everyone, we want to address the recent supply chain attack that has been nicknamed “Shai-Hulud” and assure you that Netchex is not impacted. What Happened A recent and widespread supply chain attack has been identified, impacting numerous software packages. You can read more about the specifics of the attack in this TechRadar article. Netchex Is Not Affected We want to be clear that our team has thoroughly investigated this matter and we can confirm that Netchex is not affected by this attack. Our systems and your data remain secure. We have taken the following steps to ensure this: - Internal Code Scanning: We have robust internal controls in place to continuously scan all of our code dependencies for any potential issues. - Third-Party Verification: A third-party security provider has also scanned our code and confirmed that none of the impacted packages are being used. - Continuous Monitoring: We utilize a Security Information and Event Management (SIEM) platform to monitor for any unusual activity across our systems. - Secure Storage: All of our secrets are securely stored using Azure Key Vaults. What You Should Do While Netchex is not affected, we recommend that you check in with your other critical vendors to ensure that they are also aware of this attack and have taken the necessary steps to protect your data. Please do not hesitate to reach out to our support team…

Netchex Not Impacted by Global Crowdstrike OutageDec 2025

Many businesses across the globe are currently experiencing outages due to an update released by a popular security vendor, Crowdstrike. As a current client or a business considering Netchex, we believe it is vital for you to know: 1. This event has not impacted Netchex services. Netchex does not utilize Crowdstrike for any internal services, and we are currently monitoring our critical vendors for any downstream impact. 2. If this event has impacted you, Crowdstrike has released guidance on how to recover. In the meantime, you and your employees can still access Netchex on non-Windows, personal, and mobile devices.

Avoid Fraud, Use Official Netchex PortalDec 2025

Several national payroll companies have become aware that a phishing campaign is currently being conducted against clients and their users using Google Ads to steal their login credentials. We are advising everyone to use and bookmark this direct link to the Netchex login portal: https://na3.netchexonline.net/n/Login/#/ Do not use Google to search for the Netchex login portal. As a precautionary measure, we advise any employees who may have entered credentials into a website found through Google to change their passwords immediately. This will help safeguard their personal and professional information. Furthermore, we have already taken steps to request the removal of the fraudulent website from Google search results. While this process may take some time, we are committed to ensuring that our clients are protected from such malicious activities. If you have any further questions or require additional assistance, please do not hesitate to contact us. We are here to support you and ensure the security of your data.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Other certifications
    List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Netchex SOC 2 compliant?
Netchex is SOC 2 compliant. On SOC2C this listing is Listed.
Can I use Netchex's SOC 2 for a vendor risk assessment?
Yes. Netchex's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Netchex penetration tested?
Netchex hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Netchex secure?
Security isn't a single yes/no, but Netchex is SOC 2 compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Netchex have a bug bounty or vulnerability disclosure program?
Netchex hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@netchex.com or via a /security page (Netchex lists a security contact).

Business & Industrial peers that completed SOC 2