Information Security Governance
Search documents
Sidetrade Advances Security Leadership with SOC 1® Type II, SOC 2® Type II Reports and ISO 27001 Certification as AI Footprint Expands
Globenewswire· 2026-01-13 07:40
Core Insights - Sidetrade has achieved SOC 1 Type II and SOC 2 Type II reports with an unmodified auditor's opinion, validating its control maturity and data protection practices [1][2] - The company has also completed a full ISO/IEC 27001:2022 recertification, confirming the effectiveness of its Information Security Management System (ISMS) [4][6] SOC Reports and ISO Certification - The SOC reporting framework provides independent assurance on the design and operating effectiveness of controls over time, with Sidetrade's reports confirming that internal controls were suitably designed and operated effectively [2][5] - SOC 1 Type II focuses on controls relevant to customer-facing applications supporting financial processing, while SOC 2 Type II covers controls across people, processes, and technology [8] - The ISO 27001:2022 recertification indicates alignment with international best practices, with no material nonconformities recorded [4][6] Operational Resilience and AI Integration - Sidetrade's successful audits occurred during a period of integration of acquisitions and expansion of its global footprint, demonstrating a level of control maturity capable of absorbing structural and technological changes [3][5] - The company's AI systems, including its agentic AI Aimie, are explicitly included in the scope of its ISO/IEC 27001:2022 certified ISMS [7] Regulatory Preparedness - The audit outcomes support Sidetrade's preparation for emerging regulatory frameworks, such as the EU AI Act, which will impose stricter expectations around risk management and transparency for AI companies [11] - The combination of SOC reports and ISO certification serves as a key trust signal for enterprises evaluating AI vendors in mission-critical financial workflows [11][12] Commitment to Security and Governance - Sidetrade emphasizes that security and compliance are designed as proactive control layers, developed to remain robust as products and market conditions evolve [5][6] - The company positions itself among AI providers that treat security assurance as a continuous operational discipline rather than a marketing milestone [12]