---
title: Does Vercel have a SOC 2 Type 2 attestation?
description: Vercel holds a SOC 2 Type 2 attestation for Security, Confidentiality, and Availability. See what the report covers, how to access it, and what you still own.
url: /kb/guide/is-vercel-soc-2-compliant
canonical_url: "https://vercel.com/kb/guide/is-vercel-soc-2-compliant"
published: 2025-11-03
last_updated: 2026-08-03
authors: Sam Ko
related:
  - /docs/security/compliance
  - /kb/bulletin/vercel-april-2026-security-incident
  - /kb/guide/supporting-compliance-with-vercel-waf
  - /docs/saml
  - /docs/networking/secure-compute
  - /changelog/expanded-audit-log-coverage-now-delivered-through-vercel-drains
  - /docs/vercel-firewall/vercel-waf
  - /docs/observability/audit-log
  - /docs/security/shared-responsibility
install_vercel_plugin: npx plugins add vercel/vercel-plugin
---

Yes. Vercel holds a SOC 2 Type 2 attestation for the [Security, Confidentiality, and Availability](https://vercel.com/docs/security/compliance) Trust Services Criteria. On its own, a yes tells you little; the useful part is the report scope and the shared responsibility boundary that sits underneath it.

Here's how to read that scope, access the report, and work out what your own audit still needs to cover.

## What does a SOC 2 Type 2 attestation cover?

SOC 2 is an attestation, not a certification. A licensed CPA firm examines an organization's controls and issues a report with an independent opinion. The [AICPA](https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2) designs the standards but grants no certification, so any vendor claiming to be "SOC 2 certified" is using the term loosely.

The Type matters as much as the framework. The three report formats differ in what they test and who can read them:

|                      | SOC 2 Type 1               | SOC 2 Type 2                                                                      | SOC 3                                |
| -------------------- | -------------------------- | --------------------------------------------------------------------------------- | ------------------------------------ |
| **Scope**            | Point-in-time snapshot     | Observation period of 3 to 12 months                                              | Same exam as Type 2                  |
| **What's evaluated** | Control design on one date | Design and operating effectiveness over the period                                | Design and operating effectiveness   |
| **Auditor tests**    | Design only                | Design plus operation, sampling access reviews, incident logs, and change records | Same tests, results not disclosed    |
| **Audience**         | Restricted use             | Restricted use                                                                    | General use, can be posted publicly  |
| **Typical use**      | Early due diligence        | Enterprise procurement                                                            | Public summary of a completed Type 2 |

A Type 2 report is the one enterprise procurement asks for, because it proves controls operated over time rather than existing on paper for a day.

There are five Trust Services Criteria in total. Security is required in every report, and Availability, Processing Integrity, Confidentiality, and Privacy are optional additions an organization scopes in based on the service it runs. A Type 2 report can still contain exceptions, and opinions range from unqualified through qualified, adverse, or a disclaimer, so read the report itself before relying on the badge.

## Which Trust Services Criteria does Vercel's SOC 2 report cover?

With the mechanics in place, the scope is the specific answer. Vercel's SOC 2 Type 2 attestation covers the [Security, Confidentiality, and Availability](https://vercel.com/docs/security/compliance) criteria. Processing Integrity and Privacy are out of scope, which matches what a hosting platform controls. Vercel runs the infrastructure layer, and you control your data processing logic.

The attestation sits inside a wider compliance portfolio. The frameworks below cover the standards enterprise reviewers check most often:

| Framework                    | Scope                                                       | Where to access             |
| ---------------------------- | ----------------------------------------------------------- | --------------------------- |
| SOC 2 Type 2                 | Security, Confidentiality, Availability                     | Trust Center, under Reports |
| ISO/IEC 27001:2022           | Certified to the 2022 edition of the standard               | Trust Center                |
| PCI DSS v4.0                 | SAQ-D AOC for service providers and SAQ-A AOC for merchants | Trust Center                |
| HIPAA                        | BAA available to eligible Pro and Enterprise teams          | Trust Center                |
| TISAX AL2                    | Assessment Level 2 for automotive and manufacturing         | ENX portal                  |
| GDPR, CCPA/CPRA, EU-U.S. DPF | Covered by the public DPA and DPF certification             | Public DPA                  |

The [Data Processing Addendum](https://vercel.com/legal/dpa) is public and confirms that third-party audits, including SOC 2 Type 2, run at least once annually.

Vercel also discloses security incidents publicly through its Security Bulletin. The April 2026 incident is documented in full, including scope and remediation, in the [security bulletin](https://vercel.com/kb/bulletin/vercel-april-2026-security-incident).

## How to access Vercel's SOC 2 attestation

Once you know the scope, the report itself lives in the Trust Center. Vercel's [Trust Center](https://security.vercel.com/) hosts the reports behind a Get access flow.

Access depends on your plan and the report you need:

- **SOC 2 report:** Available on request for Pro and Enterprise plans.
  
- **Penetration test report:** Available on Pro and Enterprise plans.
  
- **HIPAA report:** Available on Enterprise plans.
  

Open the Trust Center, go to **Reports**, select the report, and use the **Get access** flow. For access support, email `se@vercel.com` with the subject line `SafeBase Support Request for Vercel`, and a team member can help unblock the request.

## How Vercel platform features map to SOC 2 criteria

The attestation answers the question about Vercel. Several platform features then support the controls your own auditor tests, which is where the platform reduces your audit work. Vercel documents this mapping directly for the firewall in [Supporting compliance with Vercel WAF](https://vercel.com/kb/guide/supporting-compliance-with-vercel-waf); the rest of the table reflects how the remaining features line up with common criteria:

| SOC 2 criteria                          | Vercel feature                                                                                                   | What it supports                                                                                                                    | Plan                                                          |
| --------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------- |
| CC6.1 logical access                    | RBAC and Directory Sync (SCIM)                                                                                   | Least-privilege roles, with de-provisioning from your identity provider                                                             | Team roles on Pro; project-level roles and SCIM on Enterprise |
| CC6.2 to CC6.3 authentication           | [SAML SSO](https://vercel.com/docs/saml) with enforcement                                                        | Sessions that require your identity provider, across Okta, Google, Auth0, OneLogin, Microsoft Entra, and more                       | Enterprise, or a Pro add-on at $300/month                     |
| CC6.6 to CC6.7 network and transmission | [Secure Compute](https://vercel.com/docs/networking/secure-compute) with AES-256 at rest and TLS 1.3 in transit  | A dedicated VPC and static IP pair per network, isolated with no cross-team sharing, plus VPC peering to AWS                        | Enterprise                                                    |
| CC7.2 continuous monitoring             | [Audit Log Drains](https://vercel.com/changelog/expanded-audit-log-coverage-now-delivered-through-vercel-drains) | Team activity events streamed to your security information and event management (SIEM) system at $0.50/GB                           | Enterprise                                                    |
| CC7.3 incident detection                | WAF with JA3 and JA4 TLS fingerprinting                                                                          | Detection at the edge, with rule changes that [propagate globally within 300ms](https://vercel.com/docs/vercel-firewall/vercel-waf) | All plans, mitigation notifications on Pro and Enterprise     |
| CC8.1 change management                 | Deployment Protection and versioned WAF rules                                                                    | Auditable, restorable changes to protected environments                                                                             | Vercel Authentication on all plans, Trusted IPs on Enterprise |

These features don't grant you SOC 2 status, but they give your auditor documented, testable evidence for the criteria above.

### How Audit Logs give auditors an evidence trail

[Audit Logs](https://vercel.com/docs/observability/audit-log) turn platform activity into the record an auditor samples. They're available on Enterprise plans to team members with the owner role, and each record captures the timestamp, action, actor ID, actor name, actor email, IP location, user agent, request ID, and the previous and next state as JSON.

The dashboard retains 90 days of events, and owners export a CSV from **Team Settings** > **Security & Privacy** > **Audit Log**. For continuous delivery, Audit Log Drains stream events to Amazon S3, Splunk, or a custom HTTP endpoint, which replaces the earlier Custom SIEM Log Streaming feature.

Auditors sample event names such as `shared_env_variable.decrypted`, project SSO protection changes, and `auditlog.export.requested`, which supply the logical-access and change-management evidence that CC6.x and CC8.1 sampling asks for.

## Does hosting on Vercel make your product SOC 2 compliant?

No. Hosting in an attested environment doesn't transfer that attestation to your product, so your own security requirements stay in place.

In your SOC 2 audit, Vercel is a subservice organization. Under the carve-out method, the standard approach, your auditor excludes Vercel's internal controls from your scope. You still name the Complementary Subservice Organization Controls you expect Vercel to run, and you name and operate the Complementary User Entity Controls (CUECs) on your side. If a CUEC isn't operating effectively at your organization, a control failure can happen even with Vercel's attestation in place. Obtaining the SOC 2 report, reviewing it, and documenting that review is itself a tested control in your audit, typically under CC9.2.

The split follows Vercel's [shared responsibility model](https://vercel.com/docs/security/shared-responsibility):

- **Vercel's scope:** Physical security, network segmentation, employee access management, platform change management, and infrastructure patching.
  
- **Your scope:** Application access control, secrets management, code review, customer data handling, application-level encryption, and your own change management.
  
- **Shared:** Incident response, where Vercel handles infrastructure and you handle your application code and configuration.
  

Working through that split is what turns Vercel's attestation into fewer controls you have to build, document, and evidence alone.

## Next steps

To take this into your own review, request the reports and view current certificates in the [Vercel Trust Center](https://security.vercel.com/). Then confirm who owns each control by reading the [shared responsibility model](https://vercel.com/docs/security/shared-responsibility) before you scope your audit.

## Related resources

- [Security and compliance measures](https://vercel.com/docs/security/compliance)
  
- [Shared responsibility model](https://vercel.com/docs/security/shared-responsibility)
  
- [Supporting compliance with Vercel WAF](https://vercel.com/kb/guide/supporting-compliance-with-vercel-waf)
  
- [Audit Logs](https://vercel.com/docs/observability/audit-log)
  
- [Secure Compute](https://vercel.com/docs/networking/secure-compute)
  

## Frequently asked questions

### Is Vercel SOC 2 certified or SOC 2 attested?

Attested. A licensed CPA firm examines Vercel's controls and issues an independent opinion in a SOC 2 Type 2 report. The AICPA sets the standards but issues no certification, so "SOC 2 certified" is a common but imprecise phrasing. The accurate term is a SOC 2 Type 2 attestation.

### Which Trust Services Criteria does Vercel's SOC 2 report cover?

Security, Confidentiality, and Availability. Processing Integrity and Privacy are out of scope, which is consistent with a hosting and deployment platform. Vercel controls the infrastructure layer, and you control your data processing logic, so those two criteria fall to your own application audit.

### How do I get Vercel's SOC 2 report?

Visit the [Trust Center](https://security.vercel.com/), open **Reports**, select the SOC 2 report, and use the **Get access** flow. The SOC 2 report is available on Pro and Enterprise plans. For access support, email `se@vercel.com` with the subject `SafeBase Support Request for Vercel`.

### Does using Vercel make my product SOC 2 compliant?

No. Your team passes its own audit. Vercel is a subservice organization in that audit, so you implement the Complementary User Entity Controls from the report and document an annual review of it. That review is itself a tested control, typically under CC9.2.

### Which Vercel plan do I need for the compliance-relevant features?

Enterprise covers Audit Logs, Audit Log Drains, Directory Sync (SCIM), the Security role, Trusted IPs, Secure Compute, and HIPAA. SAML SSO is available on Enterprise or as a Pro add-on at $300/month. WAF protection and DDoS mitigation cover all plans, with mitigation notifications on Pro and Enterprise.