Pave receives SOC 2 Type II certification

Continuing our customer commitment with additional security certification

Elliott Gluck
Pave Compensation
Published in
2 min readFeb 23, 2021

--

Pave was founded on the premise that greater real-time transparency leads to improved outcomes & visibility for customers. With our suite of total compensation tools, we have been focused on innovating for our customers and bringing additional transparency to both the candidate and employee compensation experience. Given this relentless focus, it seemed only fitting that we also be as transparent with what is happening with our customer’s data as well. This conviction led us to begin the process to become SOC 2 Type II compliant, which we are pleased to announce we have now successfully completed!

So what is SOC 2 Type II compliance and why is it important to Pave (and our customers)? At a high level it’s an audit done that requires strict organizational and technical controls to protect our customer’s privacy and data (data which is commonly stored in the cloud). We also opted to seek Type 2 compliance which is more strict monitoring over time, in contrast to Type 1 which only measures compliance at a single point in time. Our compliance monitoring vendor, Vanta, notes that “A Type II report shows not only that you understand the necessary security procedures, but that you follow them over a period of time.” This translates to Pave being recognized as fulfilling the “gold standard” for security and privacy, both of which we care deeply about.

The process to be eligible for this certification started over 6 months ago, thanks to the diligence of our Engineering team. During that time we continued to launch new products and functionality (including the announcement of the Pave Compensation Benchmarking Project) which continued to be certified compliant by our auditors at The Cadence Group. Furthermore, we initiated this audit process far earlier than most other SaaS companies knowing how sensitive the nature of our customer’s data is and how imperative it is to deliver the highest security certification possible.

In summary, we’re thrilled to be able to announce our compliance with SOC 2 Type II. This distinction continues to drive home the importance we take in dealing with sensitive proprietary data and the trust we look to build with our customers. We’re also proud of the continued compliance over time, even as the company continues to innovate and introduce new products to the market. This is not the destination but rather another step to becoming the ultimate customer-centric company we want to build.

To learn more, visit our site to request a demo to see our product live!

--

--