SOC 2 Compliance

Your positions, your investors, and your performance data are among the most sensitive information your firm holds. PortfolioShop is SOC 2 Type 2 certified, and treats that certification as the floor for how client data is handled, not the ceiling.

AICPA SOC for Service Organizations seal HedgeWeek US Emerging Manager Awards 2023, Best Portfolio Management Software

What SOC 2 Type 2 means

SOC 2 is an attestation framework defined by the American Institute of Certified Public Accountants (AICPA). A Type 2 report goes beyond a point-in-time design review: an independent auditor examines whether our controls actually operated effectively over an extended observation period. In plain terms, our security practices are audited, not asserted.

Why it matters for investment operations

  • Due diligence, shortened. Allocators, administrators, and counterparties increasingly require SOC 2 evidence from operational vendors. Ours is standing and current.
  • Independent verification. The controls protecting your book of record are tested by an outside auditor on an ongoing basis, over time, not once.
  • Institutional-grade infrastructure. All data retention and management is handled in a SOC 1 and HIPAA-HITECH compliant data center.

Requesting our SOC 2 report

Current clients and qualified prospects may request our most recent SOC 2 Type 2 report under a non-disclosure agreement as part of their due-diligence process. Contact sales@portfolioshop.com or call (516) 364-6800 and we will coordinate delivery with your compliance team.

Questions

Security questionnaires and vendor-risk reviews are a normal part of our week. Send yours along, or request a demo and raise security topics directly with the team that operates the platform.

Book a Demo Built Around
Your Fund

Every walkthrough is built around your fund’s structure, your counterparty relationships, and the operational questions that matter most to your team.