Puzzle takes data security seriously. We use Google Cloud (GCP), Google Workspace, and Vanta for automated compliance and hardware authentication to block phishing and credential leaks. We're SOC2 compliant and committed to protecting your data. Want to see for yourself? Visit our real-time trust dashboard.
TLDR:
At Puzzle, we are dedicated to safeguarding your data like it's our own. With Vanta, we stay current with the latest compliance standards and use hardware authentication to block malicious actors. Your data is our top priority, and we take it seriously.
Keeping your data safe and secure is a core commitment. Google Cloud and Workspace provide a strong layer of protection for our evolving cloud-based operations. Thanks to their rest encryption, access controls, and 24/7 activity monitoring, we have complete confidence in warding off any potential intruders looking to make away with sensitive data and shield us from unauthorized access to data, potential theft attempts, and other malicious threats. With these features in place, we breathe easy, knowing that you are well-guarded.
We use Vanta for automated compliance monitoring: a platform that runs 1,400+ automated tests hourly across 400+ integrations to give our security team continuous visibility into the health of our infrastructure. When a control drifts or a potential gap appears, Vanta flags it in real time, so issues are caught and remediated before they become problems. This matters especially for cybersecurity startups, where compliance posture is often a direct revenue dependency.
The stakes for getting security right have never been higher. Phishing now accounts for 33.8% of SMB breaches, and AI has cut the cost of launching a phishing campaign by 95%, putting even the smallest companies squarely in attackers' crosshairs. On the compliance side, over 70% of enterprise buyers now require SOC 2 reports from their technology vendors before signing a contract, making attestation less of a nice-to-have and more of a sales prerequisite. The SOC 2 bar itself is rising: confidentiality controls now appear in 64.4% of reports, up from 34% just three years ago. These aren't hypothetical risks; they're the real conditions your financial data operates under every day. It's why Puzzle treats security as infrastructure, not a checkbox, and why accuracy you can audit is built into everything we do.
Yes. Puzzle is SOC 2 compliant. We use Vanta to run 1,400+ automated compliance tests hourly across 400+ integrations, giving our security team continuous visibility into the health of our infrastructure. When a control drifts or a gap appears, Vanta flags it in real time so issues are caught and remediated before they become problems.
Puzzle runs on Google Cloud (GCP) and Google Workspace. GCP provides encryption at rest, granular access controls, and 24/7 activity monitoring. Google Workspace enforces collaboration security and access control policies across our team. Together, they form the foundation of our cloud security posture.
We require hardware authentication keys for all team access. Hardware-based authentication means that even if a password is compromised, an attacker cannot log in without the physical key, blocking the most common vectors for phishing and credential-leak attacks.
Over 70% of enterprise buyers now require SOC 2 reports from technology vendors before signing a contract. For cybersecurity startups in particular, compliance posture is often a direct revenue dependency: without an attestation, deals stall. Puzzle's SOC 2 compliance means your accounting partner won't become a blocker in your sales process.
Puzzle publishes a real-time trust dashboard at trust.puzzle.io. The dashboard reflects our live compliance posture so you can verify our security controls at any time, with no need to wait for a manual report.
| Security Layer | Technology Used | What It Protects Against |
|---|---|---|
| Cloud Infrastructure | Google Cloud (GCP) | Unauthorized access, data theft, rest encryption, 24/7 activity monitoring |
| Workspace & Access Controls | Google Workspace | Access control enforcement, collaboration security |
| Automated Compliance | Vanta (1,400+ automated tests hourly, 400+ integrations) | Compliance drift, control gaps, SOC 2 attestation |
| Hardware Authentication | Hardware authentication keys | Phishing attacks, credential leaks, unauthorized logins |
Phishing scams and credential leaks are a real threat, and we've taken proactive measures to keep your data safe.
Our hardware authentication keys protect against unauthorized access, keeping your information secure against ever-increasing cyber threats.
At Puzzle, we are deeply committed to defending our customers' data, which is why we have implemented Google Cloud (GCP), Google Workspace, and Vanta security controls to achieve SOC2 compliance.
Rest easy knowing that your data is in good hands.





