Back to Blog
CompanyApril 24, 2026

SOC 2 Type II Certification: What It Means for Our Customers

Nutracie has achieved SOC 2 Type II compliance. Here's what changed in our infrastructure and what it means for your data.

DP

David Park

Head of Security

5 min read

We are pleased to announce that Nutracie has achieved SOC 2 Type II certification, audited by Deloitte over a six-month observation period covering the security, availability, and confidentiality trust service criteria. This certification validates that our security controls are not just well-designed (Type I) but operate effectively over time (Type II).

SOC 2 Type II is the gold standard for cloud service providers handling sensitive data. For our pharmaceutical and healthcare customers, this certification provides independent assurance that Nutracie meets the rigorous security requirements expected of a platform processing research data, intellectual property, and in some cases, protected health information.

Key controls validated during the audit include: access management with role-based controls and MFA enforcement, encryption of data at rest (AES-256) and in transit (TLS 1.3), change management processes with code review and automated testing, incident response procedures with defined escalation paths, vendor management and third-party risk assessment, and business continuity and disaster recovery capabilities.

Achieving SOC 2 Type II required significant investment in our security infrastructure. Over the past year, we implemented: a centralized SIEM (Security Information and Event Management) system for real-time threat detection, automated compliance monitoring dashboards, enhanced audit logging across all platform services, formal security awareness training for all employees, and quarterly penetration testing by NCC Group.

For existing customers, no action is required. Your data has been protected by these controls throughout the audit period. Enterprise customers can request a copy of our SOC 2 report through their account manager. For prospective customers evaluating Nutracie, the SOC 2 report can be requested through our sales team under NDA.

This certification is one milestone in our broader compliance roadmap. We are currently pursuing ISO 27001 certification (expected Q4 2026) and have achieved HIPAA compliance with BAA availability for Enterprise customers. Security and trust are foundational to our mission, and we will continue investing in the controls and certifications our customers need.

DP

David Park

Head of Security

Nutracie, Inc. · San Francisco, CA

Stay Updated

Get the latest research, product updates, and industry insights delivered to your inbox.