The Vault Completes SOC 2 Type I Examination
The Vault has completed a SOC 2 Type I examination, conducted by KirkpatrickPrice, giving institutions independent, third-party verification that our security architecture and operational controls are suitably designed to meet the commitments we make to clients.
The examination assessed the design of controls governing our platform across four Trust Services Criteria: Security, Availability, Confidentiality, and Processing Integrity. The resulting report confirms that these controls are suitably designed to meet the service commitments we make to institutional clients.
Understanding SOC 2 Type I
SOC 2 is one of the most widely recognised frameworks for evaluating how a technology provider manages and protects the data and systems it is entrusted with. A Type I examination evaluates whether an organisation's controls are appropriately designed at a specific point in time, covering areas such as access management, encryption, incident response, change management, and vendor oversight.
For institutions evaluating custody infrastructure, this provides independent, third-party verification that our security architecture and operational controls meet recognised industry standards, rather than relying on self-reported claims.
What This Means for Our Clients
For institutions working with The Vault, or evaluating us as part of a vendor selection process, this examination translates into practical benefits:
- Faster due diligence. Risk and compliance teams can rely on an independent auditor's assessment rather than starting vendor security reviews from scratch.
- A documented basis for internal risk sign-off. The report provides the kind of third-party evidence that procurement, legal, and risk committees typically require before approving a custody provider.
- Clarity on what is actually being verified. The examination covers concrete, auditable areas, including access controls, encryption practices, incident response, and change management, rather than general assurances.
- A foundation to build on. This report reflects the design of our controls at a point in time. It is one part of a broader compliance programme that will continue to expand alongside our regulatory licensing.
In practice, this means institutions can move through their own internal approval processes with fewer open questions about how The Vault manages security and operational risk.
Scope of the Examination
The examination covered the infrastructure, software, and procedures supporting The Vault's platform, including:
- Logical and physical access controls, including multi-factor authentication and role-based access.
- Encryption of data at rest and in transit.
- Formal change management and software development lifecycle controls.
- Incident response and vulnerability management processes.
- Business continuity and disaster recovery planning.
- Vendor management and oversight of subservice providers.
Part of a Broader Security and Compliance Framework
This examination adds to The Vault's existing regulatory and security foundations, which include our CySEC-issued CASP licence and VQF SRO membership in Switzerland. Together, these form part of our ongoing commitment to building custody infrastructure that institutions can independently verify, not simply take on faith.