← Back to Changelog

SOC 2

August 27, 2026

We've started our SOC 2 process with security-consultant.com.

Everything we already do to protect your data is on rize.io/security, and we'll share progress here as the audit moves along.

WHAT IS IT?

SOC 2 is an independent audit of how a company protects customer data: who can access it, how it is encrypted, how incidents are handled, and whether those controls actually operate day to day. It is the standard security review that larger customers and their procurement teams ask for before adopting a tool.

WHY IS IT IMPORTANT?

Rize captures how your team works. That data is only useful if you and your clients trust where it lives. Agencies and firms increasingly answer security questionnaires from their own clients, and a vendor without SOC 2 becomes the answer they have to explain. Finishing this removes that conversation.

It also matters for the release we shipped alongside it. Profitability, resourcing, invoicing, and permissions put rates, margins, and client contracts in Rize. The controls SOC 2 verifies are the ones that keep that data scoped to the people who should see it.

WHAT IT MEANS FOR YOU

  • If your security team needs documentation now, our current policies and penetration test summary are available on request.
  • If a client or prospect asks whether Rize is SOC 2 compliant, you can point them to this post and the security page.
  • Nothing changes in how you use Rize. The work is on our side.

Let us know if you have any questions.

Back to the release notes

Related Changelog Entries