Current status
Mercurium Analytics is in the observation period for SOC 2 Type II. Our Type I report was successfully issued in Q1 2026 covering the Security Trust Services Criterion, and the 12-month observation window for Type II runs until Q1 2027. We selected a top-tier AICPA-member audit firm and a live control-monitoring tool (Drata).
Trust Services Criteria in scope
- Security — in scope for Type I and Type II.
- Availability — being added for Type II.
- Confidentiality — being added for Type II.
- Privacy — tracked under our GDPR programme; SOC 2 Privacy criterion under evaluation.
Controls already implemented
- Documented security policies reviewed annually by leadership.
- Mandatory employee security training + phishing simulations.
- SSO enforced across every production system; MFA for all staff.
- Least-privilege RBAC with quarterly access reviews.
- Encryption in transit (TLS 1.3) and at rest (AES-256 KMS-backed).
- Centralised logging and 24/7 alerting on critical events.
- Annual third-party penetration testing.
- Incident response runbook tested quarterly; RTO 4h / RPO 15m.
- Business Continuity Plan reviewed and tabletop-tested.
What your buyer-security team can see today
- Current Type I report (available under NDA).
- Live Trust Center page with real-time control status.
- Completed industry security questionnaires (SIG, CAIQ).
- Most recent independent penetration test executive summary.
- Our data flow diagrams, sub-processor list and DPA template.
Timeline to Type II
| Milestone | Target |
|---|---|
| Type I report issued | Q1 2026 ✅ |
| Observation period ends | Q1 2027 |
| Type II audit fieldwork | Q2 2027 |
| Type II report issued | Q3 2027 |
Contact
For Type I report access, questionnaire responses or deeper control evidence, email contact@mercurium-analytics.com — we respond under NDA within 3 working days.