News & Announcements
Narva Software Renews SOC 2 Type 2 Certification
•
min read

We're proud to announce that Narva Software has successfully renewed its SOC 2 Type 2 certification, confirming that the security, availability, and confidentiality controls we put in place last year continue to hold up under real-world, day-to-day operation.
We achieved SOC 2 Type 2 certification first in 2025, earning it once shows that a company can build the right controls. Renewing it signals that those controls are not just documentation, but part of our everyday work standard.
Why Renewal Matters More Than the First Certification
SOC 2 Type 2 was never meant to be a static badge. Unlike a one-time check, it requires an independent auditor to observe how an organization's security controls actually perform over an extended period — typically several months to a year.
For our customers, that distinction matters. It means:
The processes we described in 2025 are still the processes we follow today.
Our controls have kept pace with how our products, infrastructure, and team have grown.
Independent, external verification backs all of this up.
In a landscape where security incidents and data breaches are common, a renewed SOC 2 Type 2 report is one of the clearest signals a software vendor can give that trust is being actively maintained.
A Quick Refresher: What SOC 2 Type 2 Actually Covers
SOC 2 (Service Organization Control 2) is an auditing standard from the American Institute of Certified Public Accountants (AICPA) built specifically to evaluate how technology and cloud-service companies handle customer data. It's assessed against five Trust Service Criteria:
Security — Is data protected from unauthorized access?
Availability — Are systems reliable and available when needed?
Processing Integrity — Do systems function correctly, without errors or tampering?
Confidentiality — Is sensitive information properly restricted and protected?
Privacy — Is personal data collected, used, and stored responsibly?
Certified Security Across Every Narva Software App
Our SOC 2 Type 2 certification means every app we build is backed by enterprise-grade security practices — so your team can work in Jira and Confluence with confidence.
Type 1 report checks whether controls are well-designed at a single point in time. A Type 2 report goes further, verifying that those controls actually operated effectively over an extended audit period. It's widely regarded as the gold standard precisely because it can't be gamed with a last-minute cleanup — it requires sustained, consistent execution.
What the Renewal Process Involved
To renew our certification, an independent audit firm once again examined how Narva Software operates, including:
Infrastructure — our servers, networks, and physical and cloud environments
Software — the internal systems and applications supporting our services
People — the team responsible for governance, security, and operations
Data — the types of information we store, use, or process
Processes — how we manage and document service delivery from start to finish
The audit confirmed that our security practices — role-based access control, regular security testing, active monitoring, and a documented incident response plan — remain in place and functioning as intended.
What This Means for You
With a renewed SOC 2 Type 2 certification, you can continue to count on Narva Software to:
Follow secure, independently audited processes.
Protect your data using modern encryption methods.Continuously monitor our systems for risks and vulnerabilities.
Respond quickly and effectively to potential threats.
Manage data responsibly, from collection through deletion.
Whether you're an enterprise with strict compliance requirements or a fast-moving team that simply wants peace of mind, this renewal is another concrete way we demonstrate that your trust in us is well placed — and that we intend to keep earning it, every year.
You can find our current SOC 2 report and additional compliance details at our Trust Center.






