Vermeg achieves SOC 2 Type II Compliance

Vermeg have successfully maintained the SOC 2 Type II compliance for the fourth consecutive year with Zero Deviations

Share on

Copy Link

Copy Link to Clipboard

News

Vermeg achieves SOC 2 Type II Compliance

Inside the news

At Vermeg, security, trust, and compliance are at the core of our business.

We are thrilled to announce that we have successfully maintained our SOC 2 Type II compliance for the fourth consecutive year with Zero Deviations, following an extensive audit by Ernst & Young UK (EYUK). This achievement, covering the period from December 1, 2023, to November 30, 2024, reflects our continuous investment in best-in-class security practices and our unwavering dedication to safeguarding client data.

SOC 2 Type II is a globally recognized compliance standard developed by the American Institute of Certified Public Accountants (AICPA). It is designed to ensure that organizations handling sensitive data have the necessary controls in place to meet the highest security, availability, confidentiality, and processing integrity standards.

For our clients, this compliance serves as an assurance that Vermeg:

 

  • Implements and maintains strong internal security controls.
  • Protects highly sensitive and confidential information.
  • Ensures service availability and operational integrity.
  • Maintains the security of solutions hosted on SaaS platforms.

Commenting on this milestone, our Chief Compliance Officer and Head of Vermeg’s Information Security SteerCo, Anis LOUKIL shared:

 

At Vermeg, we’re fully committed to security. Maintaining our SOC 2 Type II compliance, with Zero Deviations, proves we’re serious about protecting what matters most to our customers—their data. We’re always improving our security measures, so our clients can feel safe and confident using our SaaS hosted Solutions”.


Maintaining SOC 2 Type II compliance requires a rigorous, independent audit process that assesses our adherence to security best practices. The assessment included:

 

  • Infrastructure: The physical and hardware components of a system Including Servers computers, internet connectivity, network enablement, firewalls and security…
  • Software: The programs and operating software of the system aimed to help data processing
    Data: The information used and processed by the system.
  • People: The staff involved in the operation, the management, security, and governance of the system.
  • Policies and Procedures: The automated and manual policies and procedures involved in the operation of a system.

 

Looking ahead, we’re not only committed to maintaining this level of excellence but also to continuously evolving it “- Anis LOUKIL

 

Existing and prospective clients can request Vermeg’s SOC 2 Type II report, subject to a non-disclosure agreement (NDA). For more information, please reach out to Vermeg’s Sales Representatives.

Download Our Latest CSR Report

Vermeg’s CSR policy for the redaction of the annual CSR Report.

References

https://www.aicpa-cima.com/

Share on

Copy Link

Copy Link to Clipboard