Resources
Puzzle SOC2 Compliance Update – September 2026

Puzzle SOC2 Compliance Update – September 2026

Your data, your control.

Andrew Robinson, CPA
4.11.23
In article:

Puzzle takes data security seriously. We use Google Cloud (GCP), Google Workspace, and Vanta for automated compliance and hardware authentication to block phishing and credential leaks. We're SOC2 compliant and committed to protecting your data. Want to see for yourself? Visit our real-time trust dashboard.

TLDR:

  • Phishing accounts for 33.8% of breaches against startups, and AI cut campaign costs by 95%
  • Over 70% of enterprise buyers require SOC 2 reports before signing a contract with vendors
  • Hardware authentication keys block phishing attacks even when passwords are compromised
  • Puzzle is SOC 2 compliant, running on Google Cloud (GCP) with Vanta monitoring 1,400+ automated tests hourly

Your data, your control

At Puzzle, we are dedicated to safeguarding your data like it's our own. With Vanta, we stay current with the latest compliance standards and use hardware authentication to block malicious actors. Your data is our top priority, and we take it seriously.

Protect your data with confidence

Keeping your data safe and secure is a core commitment. Google Cloud and Workspace provide a strong layer of protection for our evolving cloud-based operations. Thanks to their rest encryption, access controls, and 24/7 activity monitoring, we have complete confidence in warding off any potential intruders looking to make away with sensitive data and shield us from unauthorized access to data, potential theft attempts, and other malicious threats. With these features in place, we breathe easy, knowing that you are well-guarded.

Vanta for automated compliance

We use Vanta for automated compliance monitoring: a platform that runs 1,400+ automated tests hourly across 400+ integrations to give our security team continuous visibility into the health of our infrastructure. When a control drifts or a potential gap appears, Vanta flags it in real time, so issues are caught and remediated before they become problems. This matters especially for cybersecurity startups, where compliance posture is often a direct revenue dependency.

The threat environment in 2026

The stakes for getting security right have never been higher. Phishing now accounts for 33.8% of SMB breaches, and AI has cut the cost of launching a phishing campaign by 95%, putting even the smallest companies squarely in attackers' crosshairs. On the compliance side, over 70% of enterprise buyers now require SOC 2 reports from their technology vendors before signing a contract, making attestation less of a nice-to-have and more of a sales prerequisite. The SOC 2 bar itself is rising: confidentiality controls now appear in 64.4% of reports, up from 34% just three years ago. These aren't hypothetical risks; they're the real conditions your financial data operates under every day. It's why Puzzle treats security as infrastructure, not a checkbox, and why accuracy you can audit is built into everything we do.

Frequently Asked Questions

Is Puzzle SOC 2 compliant?

Yes. Puzzle is SOC 2 compliant. We use Vanta to run 1,400+ automated compliance tests hourly across 400+ integrations, giving our security team continuous visibility into the health of our infrastructure. When a control drifts or a gap appears, Vanta flags it in real time so issues are caught and remediated before they become problems.

What cloud infrastructure does Puzzle use to protect my data?

Puzzle runs on Google Cloud (GCP) and Google Workspace. GCP provides encryption at rest, granular access controls, and 24/7 activity monitoring. Google Workspace enforces collaboration security and access control policies across our team. Together, they form the foundation of our cloud security posture.

How does Puzzle prevent phishing and credential theft?

We require hardware authentication keys for all team access. Hardware-based authentication means that even if a password is compromised, an attacker cannot log in without the physical key, blocking the most common vectors for phishing and credential-leak attacks.

Why does SOC 2 compliance matter for startups?

Over 70% of enterprise buyers now require SOC 2 reports from technology vendors before signing a contract. For cybersecurity startups in particular, compliance posture is often a direct revenue dependency: without an attestation, deals stall. Puzzle's SOC 2 compliance means your accounting partner won't become a blocker in your sales process.

Where can I verify Puzzle's current security and compliance status?

Puzzle publishes a real-time trust dashboard at trust.puzzle.io. The dashboard reflects our live compliance posture so you can verify our security controls at any time, with no need to wait for a manual report.

Security LayerTechnology UsedWhat It Protects Against
Cloud InfrastructureGoogle Cloud (GCP)Unauthorized access, data theft, rest encryption, 24/7 activity monitoring
Workspace & Access ControlsGoogle WorkspaceAccess control enforcement, collaboration security
Automated ComplianceVanta (1,400+ automated tests hourly, 400+ integrations)Compliance drift, control gaps, SOC 2 attestation
Hardware AuthenticationHardware authentication keysPhishing attacks, credential leaks, unauthorized logins

Hardware authentication to block phishing and credential leaks

Phishing scams and credential leaks are a real threat, and we've taken proactive measures to keep your data safe.

Our hardware authentication keys protect against unauthorized access, keeping your information secure against ever-increasing cyber threats.

At Puzzle, we are deeply committed to defending our customers' data, which is why we have implemented Google Cloud (GCP), Google Workspace, and Vanta security controls to achieve SOC2 compliance.

Rest easy knowing that your data is in good hands.

Let us help you solve your financial puzzles.

Thank you for being part of our Puzzle community. Stay tuned!
Oops! Something went wrong while submitting the form.
You can unsubscribe at any anytime.

Newsroom