Overview
Emma has successfully completed a SOC 2 Type II audit, demonstrating that our controls are appropriately designed and operate effectively over time to protect customer data.
SOC 2 is an independent auditing standard developed by the American Institute of Certified Public Accountants that evaluates how companies manage data based on strict security criteria.
Emma’s SOC 2 Type II Attestation
Standard: SOC 2 Type II
Criteria covered: Security
Audit type: Independent third-party assessment
Result: Controls designed and operating effectively
SOC 2 Type II evaluates not only the design of controls, but also their effectiveness over an extended period. This provides assurance that Emma consistently protects customer data in real-world conditions.
Type I vs Type II
SOC 2 reports come in two types:
Type I evaluates whether controls are properly designed at a specific point in time
Type II evaluates whether those controls operate effectively over an extended period
Emma has achieved SOC 2 Type II, which provides stronger assurance that our controls are consistently applied in practice.
Scope
The SOC 2 Type II audit covers the Emma platform and the supporting infrastructure used to deliver our services.
This includes:
Application infrastructure
Data storage and processing
Access controls and authentication
Monitoring and incident response
What this means for customers
Emma’s SOC 2 Type II attestation provides assurance that:
Your data is protected by robust security controls
Controls are continuously enforced and monitored
Risks are actively managed and mitigated
An independent auditor has verified our practices
Access to the SOC 2 report
The full SOC 2 Type II report contains detailed information about our systems and controls and is therefore not publicly available.
We provide access to the report to customers and partners with a legitimate need, under NDA.
Continuous security commitment
SOC 2 Type II is part of Emma’s broader security and compliance program, which includes ongoing monitoring, internal reviews, and continuous improvement of our controls and processes.

