In short: ProBackup has been SOC 2 Type II certified since May 2025. The latest report covers 1 April to 30 June 2026 and can be requested through the trust centre at trust.probackup.io. It evidences how ProBackup protects the backup data it holds. It is not an ISO 27001 certificate, and it does not make your own organisation compliant with anything.
If you are evaluating a backup vendor, someone in procurement or security will ask for the SOC 2 report. This page explains what ours covers, how to get it, and what it does not prove.
What SOC 2 is (and is not)
SOC 2 is an attestation framework published by the AICPA, the American Institute of Certified Public Accountants. An independent auditor examines a service organisation's controls against the Trust Services Criteria (TSC), which cover five categories: security, availability, processing integrity, confidentiality and privacy. Security is mandatory; the other four are included when relevant to the service.
Two report types exist. A Type I report assesses whether controls are suitably designed at a single point in time. A Type II report assesses whether those controls operated effectively across a review period, typically several months. Type II is the one that matters for a vendor you will rely on continuously, because it shows the controls held up over time rather than on the day of the audit.
SOC 2 is not a regulation and not a certificate in the ISO sense. The output is an auditor's report with an opinion, which is why the precise wording is "SOC 2 Type II report" or "SOC 2 Type II certified". The substance is in the report's scope, the auditor's opinion and any exceptions listed, not in a logo.
ProBackup's report: dates and scope
- Certified since: May 2025, when ProBackup's first SOC 2 Type II report was issued.
- Latest report period: 1 April 2026 to 30 June 2026. Reports are renewed on a rolling basis, so this line is updated whenever a new period is issued.
- Scope: the ProBackup service that takes daily snapshots of connected cloud apps, stores them and restores them. Controls cover the infrastructure (AWS, with S3 storage in one of nine regions selected by the customer), encryption (AES-256 at rest, TLS in transit), access control (two-factor authentication for users, SSO on Premium, MFA and least-privilege access for ProBackup staff), change management, monitoring, vendor management and incident response.
- Related evidence: an annual third-party penetration test report and the Data Processing Addendum sit alongside the SOC 2 report.
Which criteria relate to backup and availability
Buyers of a backup service usually care about three areas of the TSC. Described generically, per the AICPA's criteria:
- CC7.5 (Security, "System operations") asks whether the organisation identifies, develops and implements activities to recover from identified security incidents. For ProBackup this is the incident-response and recovery procedure for the backup platform itself.
- A1.2 (Availability) asks whether environmental protections, software, data backup processes and recovery infrastructure are authorised, designed, developed, implemented, operated, monitored and maintained to meet availability objectives. This is where the auditor looks at how ProBackup's own systems and stored snapshots are protected and replicated.
- A1.3 (Availability) asks whether recovery plan procedures are tested to meet availability objectives. In plain terms: not just having a recovery plan, but exercising it.
Together these answer "if ProBackup has a bad day, is the backup copy of my data still safe and recoverable?" They cannot answer "is my Asana workspace backed up?" That is your control, covered below.
How to request the report
- Go to the trust centre at trust.probackup.io (hosted on Comp AI). It lists the SOC 2 Type II and GDPR status, the policies and controls in scope, the penetration test summary and the DPA.
- Click Request access, fill in your details and accept the non-disclosure terms. SOC 2 reports contain detail about an organisation's environment, so they are shared under NDA, which is standard practice.
- Once approved you can download the current report, and you will have access to later reports as they are issued.
The documents are also listed on the audit reports page, and the data security page summarises the controls in plain language. Security questionnaires can be sent to support and are answered from the same evidence base.
What ProBackup does not hold: ISO 27001
ProBackup does not hold ISO/IEC 27001 certification, and we do not claim it. If a questionnaire asks, the honest answer is "SOC 2 Type II, not ISO 27001".
The two frameworks overlap heavily but are not interchangeable. ISO/IEC 27001:2022 certifies an information security management system against a fixed set of requirements, with Annex A listing reference controls. The relevant one here is Annex A 8.13, Information backup, which expects backup copies of information, software and systems to be maintained and regularly tested in line with an agreed backup policy. SOC 2's availability criteria ask a closely related question in a different form; neither substitutes for the other on a questionnaire. If your organisation requires ISO 27001 from every processor, ProBackup will not meet that line item today, and we would rather you know before procurement than after.
Pulling ProBackup evidence into your own audit with Vanta
If your organisation runs its own SOC 2 programme on Vanta, ProBackup's integration lets Vanta test your ProBackup account automatically rather than relying on a screenshot at audit time. In the Vanta Integrations section, connect your ProBackup account; Vanta then runs three continuous tests:
- Accounts deprovisioned when personnel leave: ProBackup users belonging to departed staff are removed.
- User accounts associated with users: every ProBackup login maps to a named person, so there are no orphaned accounts.
- User accounts have MFA enabled: two-factor authentication is switched on for each ProBackup user.
Those tests feed Vanta controls such as remote-access MFA enforcement and unique authentication. They are evidence about your use of ProBackup, the part a vendor's own report cannot supply. Background: the Vanta integration announcement.
How a vendor's report differs from your compliance
This is the point most often misunderstood. ProBackup's SOC 2 Type II report proves that ProBackup, as a processor, protects the data it holds. Under GDPR Article 28 that is the kind of "sufficient guarantee" you are required to check before using a processor. It does not transfer your obligations to us.
Your own auditor will still ask you to show:
- That backups exist for the systems in scope. Which apps are connected, since when, and who owns the configuration.
- That retention matches policy. Version history is 6 months on Plus, 2 years on Pro and unlimited on Premium; the plan you chose should match the retention your policy states. A written SaaS data backup policy is where that decision lives.
- That restores are tested. A restore drill per quarter, with a note of what was restored and how long it took, satisfies the "tested" element in both SOC 2 A1.3 and ISO 27001 A 8.13.
- That access is controlled. Who can open the vault, who can restore, whether MFA is on. The Vanta tests above cover this automatically.
NIS2 follows the same logic for in-scope entities: the backup and recovery obligation sits with the organisation, and a processor's report is supporting evidence. See NIS2 backup requirements, and the GDPR page for how ProBackup handles personal data as a processor.
FAQ
Is ProBackup SOC 2 certified?
Yes. ProBackup has been SOC 2 Type II certified since May 2025. The latest report period is 1 April to 30 June 2026, and reports are renewed on a rolling basis.
How do I get ProBackup's SOC 2 report?
Request it at trust.probackup.io. Access is granted under NDA, after which you can download the current report and the penetration test summary and DPA.
Is ProBackup ISO 27001 certified?
No. ProBackup holds a SOC 2 Type II report, not ISO 27001. The frameworks overlap, but if your policy requires ISO 27001 from every processor, ProBackup does not meet that line item.
Does using a SOC 2 certified backup vendor make my company SOC 2 compliant?
No. Our report evidences how we protect the data we hold. Your own audit still needs to show which systems are backed up, that retention matches your policy, that restores are tested and that access is controlled; the Vanta integration automates part of that evidence.






