Saturday, July 12, 2025
HomeEmail MarketingEmail Campaign OptimizationLitmus receives independent SOC 2 Type 2 report with zero findings for...

Litmus receives independent SOC 2 Type 2 report with zero findings for fourth consecutive year

Trust, privacy and security are core principles of Litmus. Every solution we offer is designed with our customers’ security and privacy in mind.

In turn, email marketing teams like yours trust Litmus to help them earn the trust of their audience by ensuring every email is effectively personalized and optimized for each subscriber.

To demonstrate our commitment to providing trust and security to our customers, we are proud to announce that we have achieved SOC 2 Type 2 certification with zero defects for the fourth consecutive year. This year, the certification includes our Litmus Personalize solution.

AICPA SOC logo

What is the difference between SOC 2 Type 1 and SOC 2 Type 2 certification?

The main difference between SOC 2 Type 1 and SOC 2 Type 2 reports is the scope and depth of the audit performed.

SOC 2 Type 1 reports provide a point-in-time assessment of a service organization’s controls, typically within a few weeks. SOC 2 Type 2 reports provide a more in-depth assessment over a period of 3 to 12 months, examining the continued effectiveness of controls.

What does this mean to you?

Given the AICPA’s strong SOC 2 Type 2 standard, as a Litmus customer you can:

  • Finish Inner Peace Your information is handled securely and protected from unauthorized access.
  • confidently rely on Litmus solutions are available when you need them most.
  • Please be assured that the data and information you receive from Litmus is Trustworthy, accurate and complete all the time.

We keep in mind the five “Trusted Service Principles” of SOC 2 – privacy, security, availability, confidentiality and processing integrity. We’re proud to let our customers know this.

In addition to our 2023-2024 SOC 2 Type 2 reporting, we are certified for the new Data Privacy Framework (DPF) adequacy decision. The DPF is the latest effective transfer mechanism under the GDPR, allowing EU, EEA, UK and Swiss companies to transfer their personal data to US providers. We remain compliant with applicable state regulations (CCPA/CPRA, etc.) to support our commitment to trust, privacy, and security.

You can learn more about all the efforts we put into building a truly trustworthy service Our Trust Center. If you have questions about our SOC 2 compliance or any trust-related issues, please contact the Litmus team at security@litmus.com.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments