Devicie renews SOC 2 Type II compliance for 2026

Independent examination provides continued assurance that Devicie’s controls supporting security, availability and confidentiality are operating effectively.

Trust is not established through a one-time assessment.

It is earned by demonstrating that the right controls continue to operate effectively as a company, its technology and the threat landscape evolve.

Devicie has successfully completed its latest SOC 2 Type II examination and received its finalized 2026 SOC 2 and SOC 3 reports, continuing its established SOC compliance program.

Conducted by independent service auditor AssurancePoint, LLC, the examination evaluated the controls supporting the Devicie Solution over a 12-month period from May 1, 2025 to April 30, 2026.

The examination covered the AICPA Trust Services Criteria relevant to:

  • Security
  • Availability
  • Confidentiality

The independent auditor concluded that Devicie’s controls were suitably designed and operated effectively throughout the review period.

Continued assurance, not a point-in-time achievement

A SOC 2 Type II examination does more than confirm that an organization has documented security policies.

It examines whether the controls supporting those policies operated effectively over an extended period.

For Devicie customers and partners, this renewal provides continued independent assurance that security, availability and confidentiality remain embedded in how we build, operate and protect the Devicie Solution.

It also demonstrates that Devicie has continued to maintain its control environment following its previous SOC 2 Type II renewal and the addition of its SOC 3 report.

What was examined?

The examination assessed controls across the systems, people and processes supporting the Devicie Solution.

Access management and data protection

Devicie uses role-based access controls, multifactor authentication and restricted administrative access to help ensure that production systems and customer data are accessible only to authorized personnel.

Continuous security monitoring

Devicie continuously monitors its cloud environment for threats, vulnerabilities, anomalous activity and potential control failures.

The examination included controls related to security monitoring, vulnerability reviews, alerting and the investigation and remediation of security events.

Change management

Changes to Devicie software and infrastructure must be reviewed, tested and approved before they are introduced into the production environment.

The examination assessed controls covering development practices, production access, security testing and approval processes.

Availability and resilience

Production and customer data are continuously backed up to geographically separate locations. Devicie also maintains formal business continuity and disaster recovery procedures and tests its recovery processes annually.

Confidentiality

Devicie maintains policies and controls governing how confidential information is classified, transmitted, retained and securely removed when it is no longer required.

What did the examination find?

The auditor concluded that Devicie’s controls operated effectively throughout the review period to provide reasonable assurance that the company’s service commitments and system requirements were achieved.

The report also states that no incidents were identified or reported during the review period that could have impaired the achievement of those commitments and requirements.

Across the auditor’s testing of the applicable controls, no exceptions were noted.

Compliance is a continuous commitment

Renewing SOC 2 Type II is important because security and compliance do not stop when an examination ends.

Controls must continue to operate as technology changes, the product evolves and the company grows. That requires consistent attention across the business throughout the year.

“Renewing our SOC 2 Type II compliance is important because it demonstrates that our controls are not only appropriately designed, but continue to operate effectively over time. This result reflects the discipline of teams across Devicie and our ongoing commitment to earning the trust of our customers and partners.”

Glyn Geoghegan, Head of Security and Compliance at Devicie

Accessing Devicie’s reports

The SOC 2 Type 2 report is available upon request under NDA due to its technical and confidential information about our processes. The SOC 3 report is also available on request. To access these reports, contact us at learnmore@devicie.com

soc-2-3-with-space2x

Related Content

Devicie achieves AICPA SOC 2 Type 2 compliance

We’re pleased to announce that Devicie has again officially achieved SOC 2 Type 2 compliance and added SOC 3 this year. Th...
February 14, 2025
Devicie
Read More

Better together, by design: Devicie + Microsoft Security Copilot

A look at how AI, endpoint context, and human judgment come together to shape the future of device management.
April 23, 2026
Devicie
Read More

Devicie Recognized as a Finalist of 2025 Microsoft for Startups Partner of the Year

Tampa Bay, Fla. – Nov. 12, 2025 – Devicie, a leader in optimized Microsoft Intune deployment and maintenance solutions, to...
November 12, 2025
Devicie
Read More