Audited.
Continuously.
ChartVPS holds a SOC 2 Type I report and is now in its Type II observation window — operational security controls verified by an independent auditor over time, not a one-time snapshot.
Audit information
- Observation Window
- 90 days
- Observation Start
- Jun 22, 2026
- In-Scope Controls
- 71
- Auditor
- Prescient Security
- Re-Audit Cycle
- Annual
Operational Controls
Identity & Access
SSO, MFA on all remote and admin access, least-privilege RBAC, quarterly access reviews.
Quarterly Access ReviewsChange Management
Every production change is documented, peer-reviewed, tested, and formally approved before deployment.
Auditable Change LogsLogging & Monitoring
Centralized audit logging with intrusion detection and file-integrity monitoring; alerts on anomalous or tampered logs.
Audit Logging + IDSDisaster Recovery
Documented recovery procedures with automated environment replication. DR plan tested at least annually.
Annual DR TestVulnerability Management
Vulnerability scanning at least annually plus periodic external scans, findings tracked to resolution, and regular penetration testing.
Regular Pen TestingIncident Response
Defined severity levels, incident notification timeframes, post-incident reviews shared on request.
Defined Response SLAThe difference between paperwork and proof.
Type I confirms controls exist. Type II confirms they work — every day, for months on end.
SOC 2 Type I
Auditors verify that controls are designed correctly on a single point in time. A snapshot. Most VPS providers stop here.
- Point-in-time review
- Controls exist on paper
- Single audit window
SOC 2 Type II
Auditors observe whether controls actually function over a sustained window. Continuous evidence collection. The real validation.
- Operational over time
- Evidence collected daily
- Independent re-audit annually
ChartVPS vs Others
Where competitors fall short
| Criterion | ChartVPS | Generic VPS providers |
|---|---|---|
| SOC 2 Type I | Report issued | Often absent |
| SOC 2 Type II | Observation underway (since Jun 22, 2026) | Often absent or Type I only |
| Trust criteria | Security · Availability · Confidentiality | Unscoped |
| Evidence window | 90-day observation period | Snapshot only |
| Auditor | Prescient Security | Self-attestation or none |
| Customer-facing report | Type I report under NDA via trust center | Marketing PDF, if any |
| Incident notification SLA | Defined · published | Best-effort |
| Access reviews | Quarterly, evidenced | Ad-hoc |
| DR testing | At least annual, results logged | Untested |
| Encryption policy | AES-256 at rest, TLS 1.2/1.3 in transit | Varies per node |
Trust, demonstrated — not described
Request our Type I report or talk to our security team.
