Finicast Sets Data Security Standard by Successfully Completing SOC 2 Assessment
At Finicast, we continually invest in security best practices to ensure that our client’s data stays safe and secure. As a part of an on-going effort, we are excited to announce that we’ve successfully completed our SOC 2 report.
The examination was conducted by A-LIGN, a technology-enabled security and compliance firm trusted by more than 2,500 global organizations to help mitigate cybersecurity risks.
"Our customers trust Finicast with critical data and highly confidential business planning models. We are committed to the security of that data and will continue to invest in data security and protection to mitigate cybersecurity threats." According to Marco Santiago, Finicast co-founder and VP of Finance and Operations, "A-LIGN has been a true partner in working through the rigorous attestation process."
What is a SOC 2 report and what does it mean for Finicast? In this article, we will walk you through the ins and outs of a SOC 2 report and how the report symbolizes trust to clients.
What is SOC 2 report?
A SOC 2 report addresses risks associated with the handling and access of data, and can be used by a variety of organizations of any size (e.g. SaaS, colocation, data hosting, etc.) Rather than a cybersecurity assessment that evaluates specific technical configurations, a SOC 2 report focuses more on how an organization implements and manages controls to mitigate the identified risks to the different parts of an organization.
The SOC 2 audit testing framework is based off of the Trust Services Criteria (TSC), which are used to identify various risks (points of focus) an organization should consider addressing. Based on the TSCs the organization selects to be in-scope, the third-party compliance and audit firm (in our case, A-LIGN) evaluates whether the organization has the appropriate policies, procedures and controls in place to manage the identified risks effectively.
There are five Trust Services Criteria. The first criteria, Security, must be included with every SOC 2 report and is referred as the “Common Criteria”. The remaining four are optional to include:
- Security (required)
- Availability (optional)
- Processing Integrity (optional)
- Confidentiality (optional)
- Privacy (optional)
In order to pass a SOC 2 examination and receive a letter of attestation successfully, it means an organization is addressing controls in areas such as information security, access control, vendor management, system backup, business continuity and disaster relief, and more.
Who should get a SOC 2 Examination?
Organizations of all sizes and industries can benefit from a SOC 2 Examination, as the audit can be performed for any organization that provides a variety of services to its customers. A SOC 2 report highlights the controls in place that protect and secure an organization’s system or services used by its customers. The scope of a SOC 2 Examination extends beyond the systems that have a financial impact, reaching all systems and tools used in support of the organization’s system or services.
Why do I need a SOC 2?
Today, many organizations outsource their business operations and services to third-party vendors, possibly putting client data at risk. For this reason, organizations request that their vendors achieve SOC 2 compliance to demonstrate rigorous IT security standards. Some additional reasons to consider a SOC 2 report for your organization include:
- Clients will most likely request a SOC 2 sooner or later.
- SOC 2 can bring a competitive advantage to your business.
- Enhanced information security practice.
- SOC 2 helps you gain customer trust.
- Ensure your employees understand best practices.
Know your data is safe and secure with Finicast
Finicast will make the SOC 2 report available to current or potential customers upon execution of a non-disclosure agreement. We hope the steps we have taken help you and your IT teams remain confident in knowing that your data is secure with Finicast. To learn more about our security policies and initiatives, please contact Finicast’s Security Team at security@finicast.com.
Are you ready to undergo a SOC 2 audit? Check out A-LIGN’s SOC 2 Readiness Checklist to learn how close your organization is to reaching its potential.
About A-LIGN
A-LIGN is a technology-enabled security and compliance partner trusted by more than 2,500 global organizations to help mitigate cybersecurity risks. A-LIGN uniquely delivers a single-provider approach as licensed SOC 1 and SOC 2 Assessor, accredited ISO 27001, ISO 27701 and ISO 22301 Certification Body, HISTRUST CSF Assessor firm, accredited FedRAMP 3PAO, candidate CMMC C3PAO, and Qualified Security Assessor Company. Working with small businesses to global enterprises, A-LIGN experts and its proprietary compliance management platform, A-SCEND, are transforming the compliance experience.
About Finicast
Finicast provides a modern SaaS enterprise planning platform to model, plan, forecast, and track performance across organizations of all sizes. Using a proprietary data engine combined with an intuitive user experience, Finicast provides a centralized planning platform for companies that have reached the limits of traditional planning solutions due to their business scale, operational complexity, and market dynamics. Based in San Mateo, CA, Finicast serves customers across many industries and sizes. To learn more, visit www.finicast.com.