Sphere Achieves SOC 2 Type II Certification
Independent validation of Sphere’s security, availability, and compliance controls through SOC 2 Type II certification.

Sphere has completed its second consecutive SOC 2 Type II audit, independently conducted by Insight Assurance and covering a review period that extended into 2026. The report validates that our security, availability, and confidentiality controls operated effectively throughout.
A first SOC 2 Type II report shows a company built the right controls. Each subsequent one shows they held up: new products, new markets, new partners, and a larger team all operating inside the same framework.
Why Consecutive Reports Matter
SOC 2 Type II evaluates how controls perform over an extended period rather than at a single point in time. Auditors test whether access reviews actually happen, whether incidents follow documented response procedures, and whether changes ship through controlled processes, month after month.
Controls that work for a company standing still often break when the company grows. Since our last audit, Sphere has shipped new products, scaled transaction activity, and added people and systems across the platform. This year's audit also assessed a broader scope of our operations than the first, and the framework held.
Scope of the Certification
The audit assessed the systems, processes, and controls supporting Sphere's platform and APIs across three trust services criteria:
- Security
- Availability
- Confidentiality
This includes the production infrastructure that processes live customer transactions on Sphere's platform.
Compliance Is the Product
Sphere builds payment infrastructure for regulated finance. Our customers include institutions that answer to their own auditors, regulators, and risk committees, and they extend that scrutiny to every vendor in their stack. We hold our internal security posture to the same standard we build into the platform itself.
In practice, that looks like:
- Access controls and monitoring across production systems
- Secure development and change management practices
- Continuous risk assessment and tested incident response procedures
- Ongoing third-party and vendor risk management
What This Means for Customers and Partners
The SOC 2 Type II report gives compliance and procurement teams third-party evidence they can rely on during vendor due diligence, security reviews, and ongoing monitoring. Certification is a continuous exercise, and Sphere maintains a standing program of control monitoring, testing, and improvement so our security posture evolves alongside our platform and the regulatory landscape.
Customers and partners can request the full report through the Sphere team or visit our Trust Center for additional documentation, certifications, and security details.
Annual recertification is now standard practice at Sphere, alongside the ongoing work between audits that makes each report possible.
Subscribe to Sphere Blog
No spam. Just the latest releases and tips, interesting articles, and exclusive interviews in your inbox every week.






.webp)



.webp)