Airfree
Back to Legal

Legal Centre

SOC 2 Type II Summary

Last updated 1 July 2025

This policy is provided for review and must be confirmed by legal counsel before public launch.

This summary describes Airfree’s alignment with the SOC 2 framework and how customers can obtain assurance about our controls.

1. About SOC 2

SOC 2 is an attestation framework developed by the AICPA that evaluates a service organisation’s controls against the Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, and Privacy. A Type II report assesses the operating effectiveness of those controls over a period of time.

2. Our controls

Airfree designs and operates controls aligned to the Trust Services Criteria, with a primary focus on Security, Availability, and Confidentiality. These controls span access management, change management, encryption, monitoring, incident response, and vendor management, and are described in more detail in our Security Policy.

3. Obtaining the report

Where an independent SOC 2 report is available, it is provided to customers and prospective customers under a non-disclosure agreement. To request the current report or details of the reporting period, contact us via /contact.