Security standards you can trust: Mailosaur is now SOC 2 Type II attested

Learn how SOC 2 Type II provides independent validation of the controls and processes that help protect your data.

"Mailosaur is now SOC 2 Type II attested" with the SOC 2 Type II attestation badge

Oliver Bennett

October 5, 2026

|

3 minutes

Share:

Security matters to our customers – and it matters to us too. 

That’s why we’re excited to announce a new addition to our compliance credentials: Mailosaur has officially achieved SOC 2 Type II attestation.    

Alongside our existing certifications and compliance frameworks (more on those later), SOC 2 Type II provides another layer of validation that the measures protecting customer data are working as intended.  

What is SOC 2 Type II?

SOC 2 Type II is an independent attestation report issued by a licensed Certified Public Accountant (CPA) firm. It’s not a formal pass-or-fail certification, but rather an evaluation of how effectively security controls are implemented and maintained – giving organizations greater assurance that those controls are being applied consistently.   

 

Think of it like this:  

A SOC 2 Type I report, which evaluates whether security controls are suitably designed and implemented at a single point in time, is kind of like a photograph. It captures the state of those processes at that particular moment. It’s a really useful snapshot, but it’s still just a snapshot.  

A SOC 2 Type II report, on the other hand, gives you a much bigger picture. It’s less like a photograph and more like CCTV footage, providing evidence of how those controls operate over a sustained period of time.    

What’s included in a SOC 2 Type II audit?

The audit focuses on three key areas:  

Security: How we protect customer data and systems from unauthorized access. 

Availability: How we ensure our systems remain accessible to customers. 

Confidentiality: How we keep sensitive information private and secure. 

What this means for you and your business

If you’re evaluating Mailosaur as part of a security review, SOC 2 Type II can help simplify vendor due diligence and procurement processes.  

For security, compliance, and procurement teams, that can mean less time spent reviewing supplier security documentation and a smoother path through internal approval processes. 

Our CEO, Jon Mahoney, puts this milestone into perspective:  

"In an increasingly complex security environment, I’m proud that our SOC 2 Type II attestation provides further evidence of our steadfast commitment to protecting the security and privacy of our customers' data, as well as our own. 

Security isn’t something you bolt on later, nor a box-checking exercise. It must be built in from the start. This is how we continue to earn the trust of our customers, including those in high-risk sectors like finance and healthcare."

Security standards that keep on evolving

Security doesn’t stop with SOC 2 Type II.  

In addition to our latest attestation, we’re also ISO 27001 certified, PCI DSS compliant, and fully compliant with both EU and UK GDPR regulations.  

Together, these standards form part of a broader security and compliance program that continues to evolve alongside the needs of our customers and the wider industry. 

Learn more about our security standards

Want more details on how we protect your data? 

Visit our Security and Trust page or explore our compliance documentation in the Mailosaur Trust Center.