SOC2C

Is this your company? Buyers are checking Prophix here. Claim prophix.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Prophix logo

Prophix

prophix.com· Canada· 51–200 employees
Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Prophix is SOC 2 Type II compliant. Prophix also holds ISO 27001, ISO 27017, ISO 27018, GDPR, HITRUST, and CSA STAR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to the Prophix Trust Center. At Prophix, the security of customer data is of paramount importance and are committed to providing trust and transparency. We have created comprehensive information security and privacy programs to safeguard your data. Our Prophix Cloud Services undergoes regular independent third-party audits of its information security management systems (ISMS) and achieved ISO/IEC 27001 certification, a globally recognized standard. The Prophix trust model is built on three key pillars: industry leading security, robust standards compliance, and the use of advanced tech

Compliance & infrastructure

SOC 2 Type IIISO 27001ISO 27017ISO 27018GDPRHITRUSTCSA STAR
Hosting
AWS
Data handled
Credit card informationPersonal health informationOrganization and account information (e.g., name, contact details, company)Customer uploaded data (financial, budgeting, planning)

Subprocessors

16
  • A
    Amazon Web Services · Cloud infrastructure
    USA, UK, EU, Canada, Australia, Singapore, Brazil
  • D
    Datadog · Infrastructure monitoring
    USA
  • C
    ChurnZero · Customer Success Management
    USA
  • Z
    Zendesk · Customer support management
    USA
  • M
    Microsoft · Corporate collaboration and communication
    USA, Canada
  • A
    Atlassian · Statuspage
    USA
  • B
    Base · Customer advocacy and community
    USA
  • I
    Intercom · Customer support help agent
    USA
  • P
    Pendo · Product analytics, in-app training, product feedback
    USA
  • S
    Skilljar · Learning management system
    USA
  • P
    Prophix Australia Pty Ltd. · Subsidiary
    Australia
  • P
    Prophix Europe ApS · Subsidiary
    Denmark
Show all 16 subprocessors
  • P
    Prophix UK Limited · Subsidiary
    United Kingdom
  • P
    Prophix South America Services De Informatica Ltda. · Subsidiary
    Brazil
  • S
    Sigma Conso Portugal Unipessoal Lda · Subsidiary
    Portugal
  • S
    Sigma Conso SRL/BV · Subsidiary
    Belgium

Compliance leadership

The person who leads Prophix's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Prophix's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Added Prophix Data Transfer Impact AssessmentApr 2026

Added information about international data transfers and Prophix Cloud Services including our impact assessment.

Sub-processor updateApr 2026

We will be adding Intercom as a sub-processor effective May 11, 2026 to augment our self-service customer support capabilities. We have reviewed Intercom's information security policies, data protection policy, and confirm they maintain SOC2 Type 2, ISO 27001:2022, ISO 27018, ISO 27701, ISO 42001 certifications, and are GDPR compliant. For more information about Intercom, please visit trust.intercom.com.

Re-added prior reporting period SOC2 and ISAE 3402 reportsMar 2026

Based on your feedback, we have re-added the SOC2 and ISAE 3402 reports for the prior period. These can be found under Resources

Added Cradle Accounting, SOC2, Type 2 ReportMar 2026

Added SOC2, Type 2 Report for Cradle Accounting. This report can be requested for download under the Resources section. Note: Cradle Accounting was acquired by Prophix Software in November 2025.

Removal of UserVoice as a sub processorJan 2026

UserVoice has been removed as a sub processor as the service is no longer used by Prophix for tracking feature enhancements and product feedback.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Prophix SOC 2 compliant?
Prophix is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Prophix ISO 27001 certified?
According to Prophix's public trust center, Prophix is ISO 27001 certified. On SOC2C this listing is Listed.
Is Prophix ISO 27017 certified?
According to Prophix's public trust center, Prophix is ISO 27017 certified. On SOC2C this listing is Listed.
Is Prophix ISO 27018 certified?
According to Prophix's public trust center, Prophix is ISO 27018 certified. On SOC2C this listing is Listed.
Is Prophix GDPR compliant?
According to Prophix's public trust center, Prophix is GDPR compliant. On SOC2C this listing is Listed.

Answers published by Prophix

Reproduced from Prophix's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Where can I find information regarding upcoming maintenance updates and release schedules?
Upcoming scheduled maintenances events and releases can be found at https://status.prophix.cloud/ This will give you the ability to subscribe for updates to be notified of any outages, and view historical events.
Does Prophix support Single Sign-On (SSO)?
Yes, single sign-on (SSO) is supported to leading identity providers such as Microsoft Entra (formerly AzureAD), Okta, and SAML2 compatible services.
Does Prophix support role-based access controls to manage user access?
Yes, Prophix support role-based access controls to grant and restrict individual user access to product capabilities and data based on roles and groups.
What's the architecture of the Prophix platform?
Applications in the Prophix Financial Performance Platform are native web application based on an modern web technologies such as ASP.NET using RESTful APIs and SQL databases with a browser-based user interface. !Product Architecture
Does Prophix have Responsibile AI Principles?
To govern the development of new AI capabilities at Prophix, we have established core Responsible AI Principles. These principles reference our commitment to Transparency, Trust, Customer Control, and Fairness & Equity. ##### Transparency Prophix is dedicated to AI transparency, informing our customers about the AI-enabled features in our platform. We strive to keep our customers aware of AI capabilities, their benefits and limitations. ##### Trust Prophix places paramount importance to the security and data privacy of customer data, adhering to industry leading global standards, policies, and regularly monitors potential threats to protect your data. We use data only as outlined in your Cloud Services Agreement. ##### Customer control Prophix is committed to allowing customers to control their own usage of AI capabilities by permitting enabling or disabling AI features. We also actively seek feedback from our customers to develop mutually beneficial solutions to meet their requirements. ##### Fairness & equity Prophix strives to promote a fair and equitable experience for users and works actively to identify and mitigate potential biases. We are committed to testing our AI services and employing content guardrails to prevent harmful conduct. ##### Compliance Prophix has completed the TrustArc Responsible AI Certification. The TRUSTe Responsible AI Certification is the first AI certification focused explicitly on data protection and privacy. Incorporating principles of the EU AI Act, NIST AI Risk Management Framework, ISO:42001, and OECD AI Principles offers a clear framework for companies aiming to comply with core principles of responsible AI. !TRUSTe