Security compliance can feel like a box-checking exercise from the outside: a badge on a website, a line in a sales deck. From the inside, it's the opposite. It's months of unglamorous work tightening up things that were already mostly right, and proving they stayed right.
I'm happy to share that Vitruvi has completed our SOC 2 Type II audit this year, on top of our existing SOC 1 Type II certification. And I wanted to explain why that matters.
SOC 2 is an independent audit that checks how a company actually protects the data running through its systems, things like access controls, monitoring, and how it handles security incidents. The "Type II" part means an outside auditor watched those controls operate for several months, confirming we followed them consistently, not just on paper.
Vitruvi sits in the middle of some sensitive information: GIS design data, as-built records, invoicing and payment data, and increasingly, imagery our AI Field Inspector uses to validate work in the field. Our customers are fiber operators, utilities, and oil and gas companies running programs worth hundreds of millions of dollars. That's not data anyone should be casual about, ours included.
If you're currently running a vendor risk review, procurement checklist, or security questionnaire on Vitruvi, we can now provide our SOC 2 report directly, along with responses to most standard security questionnaires. That's a meaningfully shorter path to getting Vitruvi approved internally than it used to be.
If you want the details, we've put together a full rundown of our certifications and security practices on our Trust & Security page. And if you need documentation for your own procurement process, just reach out to our team and we'll get you what you need.
If you want the details, we've put together a full rundown of our certifications and security practices on our Trust & Security page. And if you need documentation for your own procurement process, just reach out to our team and we'll get you what you need.