30% off first MonthAll Promos
SOC2SOC 2 Type I Report Issued · Type II Underway

Audited.
Continuously.

ChartVPS holds a SOC 2 Type I report and is now in its Type II observation window — operational security controls verified by an independent auditor over time, not a one-time snapshot.

Audit information

Observation Window
90 days
Observation Start
Jun 22, 2026
In-Scope Controls
71
Auditor
Prescient Security
Re-Audit Cycle
Annual

Operational Controls

01

Identity & Access

SSO, MFA on all remote and admin access, least-privilege RBAC, quarterly access reviews.

Quarterly Access Reviews
02

Change Management

Every production change is documented, peer-reviewed, tested, and formally approved before deployment.

Auditable Change Logs
03

Logging & Monitoring

Centralized audit logging with intrusion detection and file-integrity monitoring; alerts on anomalous or tampered logs.

Audit Logging + IDS
04

Disaster Recovery

Documented recovery procedures with automated environment replication. DR plan tested at least annually.

Annual DR Test
05

Vulnerability Management

Vulnerability scanning at least annually plus periodic external scans, findings tracked to resolution, and regular penetration testing.

Regular Pen Testing
06

Incident Response

Defined severity levels, incident notification timeframes, post-incident reviews shared on request.

Defined Response SLA

The difference between paperwork and proof.

Type I confirms controls exist. Type II confirms they work — every day, for months on end.

Point in time
SOC2

SOC 2 Type I

Auditors verify that controls are designed correctly on a single point in time. A snapshot. Most VPS providers stop here.

  • Point-in-time review
  • Controls exist on paper
  • Single audit window
Over time
SOC2

SOC 2 Type II

Auditors observe whether controls actually function over a sustained window. Continuous evidence collection. The real validation.

  • Operational over time
  • Evidence collected daily
  • Independent re-audit annually

ChartVPS vs Others

Where competitors fall short

CriterionChartVPSGeneric VPS providers
SOC 2 Type IReport issuedOften absent
SOC 2 Type IIObservation underway (since Jun 22, 2026)Often absent or Type I only
Trust criteriaSecurity · Availability · ConfidentialityUnscoped
Evidence window90-day observation periodSnapshot only
AuditorPrescient SecuritySelf-attestation or none
Customer-facing reportType I report under NDA via trust centerMarketing PDF, if any
Incident notification SLADefined · publishedBest-effort
Access reviewsQuarterly, evidencedAd-hoc
DR testingAt least annual, results loggedUntested
Encryption policyAES-256 at rest, TLS 1.2/1.3 in transitVaries per node

Trust, demonstrated — not described

Request our Type I report or talk to our security team.

✓ SOC 2 Type I Report✓ Security Overview✓ Incident Response Summary✓ Encryption Standards
SOC 2 Type II report

Frequently Asked Questions

Type I checks that controls are designed correctly at a single point in time. Type II goes further: an independent auditor observes whether those controls actually operate over a sustained window, with evidence collected continuously. ChartVPS holds a Type I report and is currently in its Type II observation window, with annual re-audits thereafter.
Our Type I report is available under NDA, typically within one business day of your request; the Type II report will be available once the current observation window closes. Request access through our trust center or ask your account manager.
Prescient Security, an independent auditor, conducts the audit. It covers 71 in-scope controls across the Security, Availability, and Confidentiality trust criteria, with a 90-day Type II observation window and annual re-audits.
Data is encrypted with AES-256 at rest and TLS 1.2/1.3 in transit. Encryption policy is applied consistently across the fleet rather than configured per node.
We run defined incident severity levels with published notification timeframes. Disaster recovery is tested at least annually with results logged, and post-incident reviews are shared on request.