SOC2C

Is this your company? Buyers are checking Sovos here. Claim sovos.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Sovos logo

Sovos

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Sovos is SOC 2 Type II compliant. Sovos also holds ISO 27001, GDPR, and CCPA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Sovos Compliance has implemented a comprehensive security program covering all aspects of Information Security and with the intention of providing defense in depth for the protection of Sovos systems and sensitive customer information. The program is designed around the concept of utilizing the ‘least common denominator’ control – that is, the most restrictive control required by a governing regulation, law, customer requirement, or industry best practice - and applying that control to all environments and aspects of the business. This approach allows Sovos to easily meet and normally exceed a

Compliance & infrastructure

Documents

16

Compliance leadership

The person who leads Sovos's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Sovos's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Sovos appoints Accenture as new subprocessor for Support!Nov 2024

Who is Accenture, and what role will they serve? Accenture is a global professional services company that has decades of experience in IT services, consulting, and digital transformation. Known for its expertise in strategy, technology, and operations, Accenture will be handling and supporting our ticketing system, carrying out first-line troubleshooting of issues and errors reported to Sovos. By strengthening our capabilities on this front, we strive to enhance our responsiveness and service quality, helping us to deliver timely assistance for all your needs.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Subprocessors
    List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Sovos SOC 2 compliant?
Sovos is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Sovos ISO 27001 certified?
According to Sovos's public trust center, Sovos is ISO 27001 certified. On SOC2C this listing is Listed.
Is Sovos GDPR compliant?
According to Sovos's public trust center, Sovos is GDPR compliant. On SOC2C this listing is Listed.
Is Sovos CCPA compliant?
According to Sovos's public trust center, Sovos is CCPA compliant. On SOC2C this listing is Listed.
Is Sovos SOC 2 Type I or Type II?
Sovos is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.

Answers published by Sovos

Reproduced from Sovos's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

What types of data will the new sub processor have access to?
Accenture will only have access to customer data that is provided by you when reaching out to our support. You control what data we process on your behalf. Most support requests do not require you to share personal data with us, but occasionally non-sensitive data (typically name surname and address) may be included. As such, we have strict data protection policies in place with Accenture to protect your data.
How is data protected with Accenture?
We have conducted a thorough evaluation of Accenture to ensure they meet our stringent security and data protection standards. All our contractual commitments with your company will be met by Sovos and any third party involved in the delivery of our products and services, including Accenture. All data shared with them is safeguarded using robust security measures, including encryption, access controls, and continuous monitoring, as described in Sovos Data Security Schedule.
Will this new sub processor impact data processing locations?
Accenture will have limited access to your data. This partnership does not alter the processing location of our Products or the location of storage of your data. Your data may temporarily be processed by Accenture for the sole purposes of addressing your support needs, and where that takes place in a third country Sovos has agreed to Standard Contract Clauses to guarantee an adequate level of protection in the occasional processing of your personal data.
Why is this new subprocessor being appointed?
By partnering with Accenture, we can enhance our support services with new capabilities such as live chats, reduce response times, and ensure that you receive timely and effective assistance whenever you need it. This appointment is part of our commitment to continuously improving our service quality.
How does this change impact on our contract or Data Processing Agreement (DPA)?
This appointment does not require changes to your existing contract or Data Processing Agreement. However, we have updated our list of subprocessors, as outlined in our DPA, to include Accenture. This list is accessible here.

Business & Industrial peers that completed SOC 2