Security & Compliance
SOC 2 Compliance
Your positions, your investors, and your performance data are among the most sensitive information your firm holds. PortfolioShop is SOC 2 Type 2 certified, and treats that certification as the floor for how client data is handled, not the ceiling.
What SOC 2 Type 2 means
SOC 2 is an attestation framework defined by the American Institute of Certified Public Accountants (AICPA). A Type 2 report goes beyond a point-in-time design review: an independent auditor examines whether our controls actually operated effectively over an extended observation period. In plain terms, our security practices are audited, not asserted.
Why it matters for investment operations
- Due diligence, shortened. Allocators, administrators, and counterparties increasingly require SOC 2 evidence from operational vendors. Ours is standing and current.
- Independent verification. The controls protecting your book of record are tested by an outside auditor on an ongoing basis, over time, not once.
- Institutional-grade infrastructure. All data retention and management is handled in a SOC 1 and HIPAA-HITECH compliant data center.
Requesting our SOC 2 report
Current clients and qualified prospects may request our most recent SOC 2 Type 2 report under a non-disclosure agreement as part of their due-diligence process. Contact sales@portfolioshop.com or call (516) 364-6800 and we will coordinate delivery with your compliance team.
Questions
Security questionnaires and vendor-risk reviews are a normal part of our week. Send yours along, or request a demo and raise security topics directly with the team that operates the platform.