How we secure your work, protect your data, and prove it. Our controls, our compliance roadmap, and the reports we share with clients and partners - all in one place.
Last reviewed: September 2026 · Updated quarterly
TreyTech is aligning its platform and operations to the AICPA Trust Services Criteria. Our SOC 2 program covers the TreyTech app, client portal, TreyTech Pros, and the CloudKit®-backed data layer behind them. Reports are issued by an independent CPA firm and shared under NDA.
Two layers beneath us are already attested. Website hosting inherits Netlify's SOC 2 Type 2, ISO 27001, and PCI DSS attestations, available through the Netlify Trust Center. The data layer runs on Apple's platform security. TreyTech's own SOC 2 covers what those reports cannot: our people, our policies, and our controls.
| Report | Scope | Status |
|---|---|---|
| SOC 2 Type I | Security, Confidentiality - design of controls at a point in time | In progress · fast-tracked, target EOY |
| SOC 2 Type II | Security, Availability, Confidentiality - operating effectiveness over a 6-month period | Observation window opens immediately after Type I issuance |
| Penetration test | Annual third-party test of the app, portal, and API surface | Annual · summary letter on request |
| Apple platform review | App Store® review for iOS, iPadOS®, macOS®, and tvOS® apps | Current |
Access control, change management, vendor management, and incident response policies are written, owned, and reviewed annually.
Recovery objectives are published in our Business Continuity plan and tested against real scenarios.
Confidential materials are limited to the people delivering the work and governed by your signed agreement.
Nothing is pooled, profiled, or sold. Details in our Privacy Policy.
The platform runs on Apple CloudKit with every record scoped to your Apple® identity. There is no shared password store, no office server, and no single machine that holds your project.
| Area | Control | Evidence |
|---|---|---|
| Identity | Sign in with Apple on every surface; roster-gated roles for Pros | No passwords stored by TreyTech |
| Encryption | TLS 1.2+ in transit; encrypted at rest in the private CloudKit container | Apple platform security documentation |
| Access | Least privilege; clients see their engagement, Pros see assigned projects only | Record-level scoping, quarterly access review |
| Change | Reviewed builds, TestFlight® staging, App Store release | Release history |
| Contracts | Electronic signature for binding agreements and SOWs | Signed copy and audit trail per agreement |
| Payments | Apple Pay® for consults; invoiced card, ACH, or bank transfer for SOWs and project billing; TreyTech never sees full card numbers | PCI scope held by Apple and our payment processor |
| Incidents | Immediate client notification; written report within 72 hours | Incident log |
We keep the list short. Each provider is reviewed for its own security posture before it handles client data, and this list is updated when anything changes.
| Provider | Purpose | Data |
|---|---|---|
| Apple (CloudKit, Sign in with Apple, Apple Pay, APNs) | Platform, identity, payments, notifications | Account, project, and milestone records |
| E-signature provider | Contract and SOW signing | Agreement documents and signer identity |
| Calendly + Zoom | Consult scheduling and video | Name, email, meeting time |
| Netlify | Website hosting and forms · SOC 2 Type 2, ISO 27001, PCI DSS (report via Netlify Trust Center) | Contact form submissions |
Clients, partners, and prospective clients in procurement can request our SOC 2 report, penetration test summary, and completed security questionnaires. Reports are shared under a mutual NDA within five business days. Everything below goes to one inbox — put the request type in the subject line and it routes from there.
SOC 2 is a framework defined by the American Institute of Certified Public Accountants. Status shown here reflects the program as of the review date and is not itself an attestation; the report is. Commitments here are in addition to, and do not replace, the terms of your engagement agreement.
S. and other countries and regions.
Tell us what you are building. We will be in touch.