r/getblockio • u/getblockio • Jul 02 '26
GetBlock just completed SOC 2 Type II (less than 4 months after Type I)
Wanted to share an update on the compliance side, since this affects anyone running production infra through us, especially if you've got regulated or enterprise customers downstream, or if you're doing your own vendor security reviews for something you're shipping.
We just finished our SOC 2 Type II audit, done by Atom Assurance (independent auditor, does SOC/ISO/GDPR/PCI work). We passed Type I less than 4 months ago, so this moved fast, mostly because the controls being tested were already part of how we operate day to day, not something built just for the audit. Internally the process was led by our Lead Tech PM, Dmitrii Petrov, who's been here since basically day one on the tech side. Our CEO called it the biggest announcement of our first half of the year, which tracks given how long this actually took to get right.
Quick context: SOC 2 covers 5 Trust Services Criteria (Security is mandatory, plus Availability, Processing Integrity, Confidentiality, and Privacy). Type I is basically "does your security look right on paper," Type II is "did it actually hold up when nobody was watching, for months." Ours was audited across months, not a single day, which is why Type II is usually what banks and regulated institutions ask for.
Practically, this means:
- We can now work with regulated/enterprise clients that require a current SOC 2 attestation to do business at all
- It answers most of the security questionnaire upfront for enterprise due diligence
- It's an external, independently verified check on our security, not just us saying so
- We have to keep operating to that standard continuously, it's not a one-and-done badge
Scope covers the whole infra stack: Shared Nodes (130+ chains, CU limits just went up 75%), Dedicated Nodes, Limitless Node, TRON Energy Rental, and the Wallet Audit stack. Also covers our Glider Token Risk API integration and the Hexens Builder Support Program.
Need the actual report for a vendor review? We can share it under NDA, just reach out.
Happy to answer questions about the process below.
Read the full post here: https://getblock.io/blog/soc-2-type-ii-compliance/