
Our Continued Commitment to Data Security and Trust
At Rollstack, data security has always been central to the way we build our platform and support our customers. Our product helps leading companies automatically create and update presentations and documents using trusted business data from BI tools, CRMs, spreadsheets, and data warehouses. Because our customers rely on Rollstack to work with sensitive business information, protecting that data is one of our highest priorities.
Last July, we announced that Rollstack had achieved SOC 2 Type I compliance, an important milestone that validated the design and implementation of our security controls at a specific point in time. Today, we are proud to share that Rollstack achieved SOC 2 Type II compliance in December, demonstrating that those controls have operated effectively over time.
What is SOC 2 Type II?
SOC 2 is a security framework governed by the American Institute of Certified Public Accountants, AICPA. It is designed to help service organizations demonstrate that they have the right controls in place to protect customer data.
SOC 2 reports are based on the Trust Services Criteria, which include Security, Availability, Processing Integrity, Confidentiality, and Privacy. Every SOC 2 report covers Security, and organizations may include additional criteria depending on their business needs and customer requirements.
There are two main types of SOC 2 reports:
A SOC 2 Type I report evaluates whether a company’s controls are properly designed and implemented at a specific point in time.
A SOC 2 Type II report goes further. It evaluates whether those controls not only exist, but also operate effectively over a period of time. This makes Type II an important milestone for companies that want to give customers stronger assurance around their security practices.
From SOC 2 Type I to SOC 2 Type II
When we achieved SOC 2 Type I compliance last July, it marked the beginning of a deeper and more structured security journey for Rollstack. It allowed us to validate the foundations of our security program and create a standardized way to communicate our practices to customers, partners, and stakeholders.
Since then, our team has continued to strengthen the policies, processes, and controls that support our platform. Achieving SOC 2 Type II in November reflects our ongoing commitment to maintaining these standards in our day-to-day operations, not just at a single moment in time.
We continued working with Vanta to support our compliance program, and Advantage Partners served as the CPA firm that performed our audit. This process helped us further formalize our security practices and ensure that they are consistently applied across the organization.
What This Means for Our Customers
For our customers, SOC 2 Type II provides added confidence that Rollstack takes data security seriously and that our controls have been independently evaluated over an extended period.
This milestone reinforces our commitment to:
- Protecting customer data with strong security practices
- Maintaining a reliable and trustworthy platform
- Continuously improving our internal controls and processes
- Giving customers a clear, standardized view of our security posture
As Rollstack continues to grow, we know that trust must be earned continuously. SOC 2 Type II is an important step in that journey, but it is not the end of our work. We will continue investing in security, compliance, and operational excellence so our customers can confidently use Rollstack to automate their most important reporting workflows.
Visit the Rollstack security page to learn more.
Connects to the tools you already use
All integrations