SOC 2 company profile

SPS Commerce SOC 2 status and provider evidence

Review SPS Commerce’s public SOC 2 statement, report type, evidence source, and freshness.

SOC 2 statusself attested
Report typeType II
Providers found0
Last checked2026-08-29
Providers

SPS Commerce’s SOC 2 stack

No provider is named on the current source.

We will update this page if the company publishes more detail.

Primary compliance evidence

SPS Commerce public statement

ructure runs on AWS with encryption at rest and in transit, active intrusion detection, and disaster recovery built into the architecture. We hold ISO/IEC 27001, SOC 1 Type 2, and SOC 2 Type 2 certifications, and run independent penetration testing on a regular cadence. A dedicated security team owns this work full-time, backed by a secure development lifecycle and continuous employee training. We're also RH-ISAC members and carry cyber insurance.

Classification: self attested · checked 2026-08-29
Open source ↗
SOC 1SOC 2SOC 3Type IType IIAudit readinessTrust centersVendor riskSecurity evidenceProcurement