ReportsFP&A Software with SOC 2 Compliance
Verified Research

FP&A Software with SOC 2 Compliance: The Verified 2026 Table

We checked 14 planning vendors' own trust and security pages so your security review starts from facts, not sales decks. Where a vendor doesn't publish something, this page says so.

Verified September 23, 2026For finance and IT security teams 16 min read

The Short Answer

Most established FP&A platforms now hold a SOC 2 Type II attestation. As of September 23, 2026, 12 of the 14 vendors on this page publicly document one on their own trust or security pages, including Pigment, Anaplan, Workday Adaptive Planning and Prophix. So the useful question in 2026 is not "does the vendor have SOC 2". It is "what does the report actually cover, and what sits outside it".

Two vendors on this page do not state the detail publicly. OneStream references SOC 1 and SOC 2 reporting in its service documentation without naming the report type on public pages, and Datarails states SOC 2 compliance without specifying Type I or Type II. Neither is a red flag by itself. Both are established vendors, and OneStream also holds FedRAMP authorization, which is a harder bar than SOC 2. It just means your security review starts by requesting the current reports rather than reading a public page.

How to use this page

The table in chapter 3 shows what each vendor publicly documents: SOC 2 status, ISO 27001 and other attestations, with the source. Where something is not publicly documented, the table says so, and your move is to request the evidence in your security review, not to assume it exists or doesn't. Chapters 4 to 6 cover what a SOC 2 badge does not answer: SSO and SCIM, data residency, subprocessors, pen tests and access-control depth.

One framing point before the detail. A SOC 2 report is evidence for your vendor risk process, not a substitute for it. Every vendor in this table clears the baseline that would have made them stand out in 2020. What separates them now is scope, depth and the operational controls you can only verify by asking. Finance and IT teams use the CFO Shortlist app to weigh these vendors against their own security requirements and systems stack, and this page is the compliance layer of that evaluation.

What SOC 2 Type II Actually Covers (and What It Doesn't)

SOC 2 is an attestation framework from the AICPA, the US accounting standards body. An independent CPA firm examines a vendor's controls against the Trust Services Criteria and issues a report. Your auditors know the format well, which is why SOC 2 became the default artifact in SaaS security reviews. But the two report types answer different questions, and the difference matters more than most sales decks admit.

Type I versus Type II

SOC 2 Type I

A point-in-time assessment. The auditor checks that controls were suitably designed on a single date. It says nothing about whether anyone followed those controls the week after. Vendors early in their compliance program get Type I first because it is faster. Treat it as a promissory note, not proof.

SOC 2 Type II

An operating-effectiveness assessment. The auditor tests whether controls actually worked over an observation period, usually 6 to 12 months, and reports exceptions where they didn't. This is the report your security team should ask for, and the one this page tracks.

The five Trust Services Criteria

A SOC 2 report does not have a fixed scope. Vendors choose which criteria to include, and only one is mandatory. When two vendors both say "SOC 2 Type II", their reports can cover very different ground.

  • SecurityMandatory
    Protection against unauthorized access, both physical and logical. Every SOC 2 report covers this one. It is the baseline, not a differentiator.
  • AvailabilityOptional
    Whether the system meets its uptime and resilience commitments. Relevant for planning tools your close calendar depends on. Check whether the vendor included it.
  • ConfidentialityOptional
    Controls over data designated as confidential. Your forecasts, headcount plans and M&A models fall in this bucket. Most serious FP&A vendors include it.
  • Processing integrityOptional
    Whether processing is complete, accurate and authorized. Rarely included. For a system that transforms your GL data, it is worth asking why not.
  • PrivacyOptional
    Handling of personal information against the vendor's privacy notice. Matters most when workforce planning puts employee-level compensation data in the tool.

Why a clean report is not a rubber stamp

Security teams already know this. Finance readers sometimes don't, and it changes how you read vendor claims. Four limits matter in practice.

First, the vendor defines the system boundary. A report can cover the core platform but not a newly acquired module, a beta AI feature or a regional deployment. Second, the observation window ends months before you read the report. A report issued in March covering the prior calendar year says nothing about the current quarter, which is what bridge letters are for. Third, most reports use the carve-out method for subservice organizations: the vendor's cloud provider and key subprocessors are excluded from testing, with their controls assumed. Fourth, a report can be "clean" overall while listing control exceptions in the detail. Nobody reads the exceptions on a badge.

The practical rule

Never accept the badge as the answer. Request the actual report under NDA, read the auditor's opinion, the scope section, the criteria included and the exceptions list, and ask for a bridge letter covering the period since. Every legitimate vendor on this page can support that request. A vendor that resists it is telling you something.

A note on ISO 27001, since the table tracks it too. ISO 27001 certifies that the vendor operates a conforming information security management system, audited by an accredited certification body on a three-year cycle with surveillance audits. It proves a system of management exists. SOC 2 Type II attests that specific controls operated over a period. They overlap heavily but answer different questions, which is why mature vendors carry both, and why European buyers often weight ISO 27001 more.

The Verified Table: 14 Vendors, Their Own Words

Everything below was checked against each vendor's own trust center or security page on September 23, 2026. We report what they publicly document, no more. "Not publicly documented" does not mean a vendor lacks the attestation. It means you should request the evidence in your security review instead of assuming. Certifications lapse and get renewed, so treat this as your starting checklist, not a permanent record.

VendorSOC 2 status (as publicly documented)ISO 27001Other attestationsSource
Workday Adaptive PlanningSOC 1 Type II, SOC 2 Type II and SOC 3, with Adaptive Planning named in scopeISO 27001, 27017, 27018 and 27701FedRAMP Moderate, HIPAA, ISO 42001 and a long list of regional programsworkday.com trust pages
AnaplanSOC 1 Type 2 and SOC 2 Type 2ISO 27001, 27017, 27018, 27701 and 42001CSA STAR Level 1, Cyber Essentials, ENS, TX-RAMP, EU-US Data Privacy Framework, BYOK add-ontrust.anaplan.com
OneStreamSOC 1 and SOC 2 referenced in service documentation; report type not stated on public pages, request the current reports in your security reviewISO 27001 (certification announced August 2022)FedRAMP ATO, CSA CAIQ, BYOK support, CIS benchmark hardeningonestream.com and product documentation
BoardSOC 1 Type II, SOC 2 Type II and SOC 3ISO 27001:2022, 27017, 27018 and 9001Microsoft Azure hosting; SOC reports available on requestboard.com/governance-and-compliance
PigmentSOC 1 and SOC 2 Type 2, audited annuallyISO 27001 certifiedGDPR and CCPA program, SOX-relevant controls, EU AI Act aligned AI governance, SecNumCloud sovereign hosting option via S3NSpigment.com/security and trust.pigment.com
JedoxSOC 1 and SOC 2 Type IIISO 27001, 27017 and 9001CSA STAR Levels 1 and 2, GDPR programjedox.com Trust Center and knowledge base
PlanfulSOC 1 Type 2 and SOC 2 Type 2ISO 27001:2022 and ISO 27701HIPAA business associate addendumtrust.planful.com
ProphixSOC 2 Type II, plus ISAE 3402 Type 2ISO 27001, 27017 and 27018HITRUST, TrustArc Responsible AI certification, AWS hostingprophix.com/security and trust.prophix.com
VenaSOC 1, SOC 2 Type II (audited by Deloitte) and SOC 3Not publicly documented for Vena itself; its AWS and Azure data centers are ISO 27001 certified. Confirm in your security review.TRUSTe privacy certification, CSA Trusted Cloud Provider, GDPR and PIPEDA programsvenasolutions.com/trust
DrivetrainSOC 1 Type II and SOC 2 Type IIISO 27001 certifiedGDPR program, EU or US data residency, no customer data used for AI model trainingdrivetrain.ai/trust-and-security
AbacumSOC 2 Type IIISO 27001, certified by an ANAB-accredited bodyGDPR programabacum.ai/product/security
AlephSOC 1 Type II and SOC 2 Type IINot publicly documented, request evidence in your security reviewAnnual third-party penetration test, Google Cloud hosting, SCIM directory syncgetaleph.com/platform/security
CubeSOC 2 Type IINot publicly documented, request evidence in your security reviewHIPAA-compliant data handling, AWS hosting, full audit logscubesoftware.com/security
DatarailsSOC 2 stated; report type not specified publicly, request the report in your security reviewStates it meets the ISO 27001 standard; confirm certificate versus alignmentGDPR program, penetration test summary available on requestdatarails.com compliance documents

How to read this table

The deepest publicly documented postures belong to the enterprise platforms. Workday Adaptive Planning names the product in scope across SOC 1, SOC 2 Type II, SOC 3, four ISO standards and FedRAMP Moderate, which reflects Workday's HR-data heritage. Anaplan runs a self-serve assurance portal listing SOC 1 Type 2, SOC 2 Type 2 and five ISO standards including ISO 42001 for AI governance. If your organization sells to governments or handles regulated data, these two plus OneStream (FedRAMP ATO) clear bars the rest of the market doesn't attempt.

In the mid-market tier, Prophix stands out with three ISO standards, HITRUST and an ISAE 3402 Type 2, the European sibling of SOC 1, which helps with EU audit committees. Board and Jedox both carry ISO 27001 plus SOC 2 Type II, in line with their DACH-heavy customer bases. Pigment documents SOC 1, SOC 2 Type 2 and ISO 27001, plus two things nobody else in this table offers: a French sovereign-cloud hosting option on S3NS (SecNumCloud certified) and an AI governance framework aligned to the EU AI Act. For European buyers with data sovereignty requirements, that combination is currently unique among modern planning platforms.

Two nuances are worth flagging honestly. Vena documents a strong SOC lineup audited by Deloitte, but the ISO 27001 claim on its trust page attaches to its AWS and Azure data centers, not to Vena itself. That is a common and legitimate posture, but it is not the same thing as company-level certification, so ask the direct question. Datarails says it "meets the ISO 27001 standard", which may mean certified or may mean aligned. The difference is an accredited auditor. Ask for the certificate number and issuing body, a 30-second question that settles it.

Beyond SOC 2: What Security Teams Should Actually Ask

Once every shortlisted vendor clears the SOC 2 bar, the badge stops discriminating. These five areas are where planning vendors genuinely differ, and where problems surface after signature if nobody asked before.

1. SSO and SCIM provisioning

SAML 2.0 or OIDC single sign-on should be enforced for every user, including admins, and SCIM should push joiners, movers and leavers from your directory automatically. Planning tools hold compensation and forecast data, so an ex-employee with a still-live local login is a real incident, not a theoretical one. Among the vendors here, Pigment documents SAML 2.0 SSO with SCIM provisioning, Aleph documents SCIM directory sync alongside Google and Microsoft SSO, and Drivetrain documents SAML 2.0 with Okta and Microsoft Entra ID support plus domain allowlisting. Anaplan adds IP allowlists and a BYOK encryption add-on at the enterprise end. Two questions to ask every vendor: is SSO included in my tier or priced as an add-on, and can local password login be fully disabled?

2. Data residency

If you operate under GDPR, Schrems II fallout or industry-specific localization rules, "we host in the cloud" is not an answer. Pigment documents hosting in Frankfurt or Oregon with a SecNumCloud sovereign option for France. Drivetrain documents Frankfurt or Virginia. Vena documents hubs in Canada, the US and EU regions. The enterprise suites (Workday, Anaplan, OneStream, Board, Jedox) all operate EU regions contractually. The traps are in the second-order questions: where do backups replicate, where does support staff access data from, and does the AI feature route prompts to a US-hosted model even when your tenant is in Frankfurt? Get region commitments into the order form, not the email thread.

3. Subprocessors, especially AI

Every vendor in this table now ships AI features, and nearly every AI feature adds a model provider as a subprocessor. Pull the subprocessor list and check three things: retention terms for prompts and outputs, whether your data can be used for model training, and whether AI features can be disabled per workspace while you evaluate. Drivetrain states it does not use customer data to train or fine-tune models and negotiates zero-data-retention terms with model providers. Board states customer data and AI interactions are never used to train shared models. Anaplan and Prophix both carry AI-governance attestations (ISO 42001 and TrustArc Responsible AI respectively). Whatever the posture, subscribe to the subprocessor change feed, because the list you approved at signing will not be the list a year later.

4. Penetration testing

Annual third-party penetration testing is the floor for any vendor holding your forecast. Pigment documents yearly third-party audits, pen tests and red team exercises. Aleph documents at least one third-party pen test per year. Datarails makes a pen test summary available through its compliance documents. Most others cover this under their SOC 2 control set without publishing detail, which is normal. Ask for the latest summary letter, the testing firm's name, the scope and whether critical findings were remediated and retested. A vendor that runs a public bug bounty or continuous testing program on top is signaling maturity beyond the audit cycle.

5. RBAC depth

This is the one finance teams feel daily and security questionnaires miss. Planning data is unusual: the same model holds board-level strategy, entity P&Ls and individual salaries, and hundreds of budget owners need partial access. Surface-level roles (admin, editor, viewer) are not enough. In the demo, test whether access can be restricted by dimension: entity, cost center, account range, scenario and version. Test whether a sales director can see their region's plan but not the acquisition scenario. Drivetrain, for example, documents masking of confidential compensation fields and AI that operates within each user's permissions, which is the right pattern: ask every vendor whether their AI assistant respects row-level security, because an AI that answers "what is our CFO's salary" for any user is an access-control failure with a friendly interface. Our EPM data integration guide covers the related question of credential handling in ERP connectors.

Compliance at Startup-Tier Vendors, Honestly

A decade ago, SOC 2 Type II separated enterprise-ready vendors from startups. That signal is gone, and it is worth being precise about why. Compliance automation platforms (Vanta, Drata, Secureframe and peers) now instrument a startup's stack, map controls and keep evidence collection continuous, which cut the cost and time of a first SOC 2 from a year to a quarter. Pigment itself started its SOC 2 program on Vanta before scaling into ISO 27001 and sovereign hosting. The result: Abacum, Aleph, Cube and Drivetrain, all far smaller than the suite vendors, all document current SOC 2 Type II attestations, and Aleph and Drivetrain document SOC 1 Type II as well.

So the honest read is not "small vendors are risky". It is that the same badge carries different weight at different company sizes, in both directions. Here is what actually differs.

What is usually thinner at a startup-tier vendor: the security team behind the controls may be a handful of engineers with a part-time CISO. The audit history is shorter, sometimes one or two cycles, so there is less evidence of controls surviving growth, reorgs and incident pressure. Report scope tends to be narrower, with fewer optional trust criteria included. Optional attestations like ISO 27001 come later, which is why Aleph and Cube show "not publicly documented" in that column while Abacum and Drivetrain, similar-sized companies, already hold it. And enterprise features like BYOK, customer-managed audit log streaming or sovereign hosting are usually absent from the roadmap entirely.

What is often better: a five-year-old vendor has no legacy estate. One modern codebase, one cloud, infrastructure as code, SSO built in from the first release rather than retrofitted across acquired products. When a suite vendor's SOC 2 covers a platform assembled from four acquisitions, the uniform badge can hide very non-uniform internals. A startup's report usually describes exactly the system you are buying.

The right questions for a young vendor

Skip the questionnaire theater and ask five things. How many consecutive Type II cycles have you completed, and can we see the trend in exceptions? Who owns security internally, and is it their full-time job? Which trust criteria are in scope, and why are the missing ones missing? What happens to our data and your controls if you are acquired? And can we see your incident history, not just your incident response policy? Straight answers to these tell you more than any badge wall.

One more honest note: vendor viability is a security question too. If a vendor shuts down or gets acquired, your data handling terms travel with the change of control clause in your contract, not with the SOC 2 report. For venture-backed vendors, weigh funding stage and runway alongside the compliance table. Our 2026 FP&A software ranking covers vendor durability as part of overall fit.

The Security-Review Checklist

Twelve items, in the order a well-run review asks them. Send the first eight to the vendor before the demo. Test the last four during it. A vendor that handles this list quickly and completely is showing you what their security operation looks like under mild pressure, which is exactly the information you want.

1
Request the actual SOC 2 Type II report, not the badge
Most vendors share it under NDA through a trust center. Read the auditor's opinion, the scope, the observation window and the exceptions list. A qualified opinion or a long exceptions list changes the conversation.
2
Check the report covers the product you are buying
Suites grow by acquisition. Confirm the FP&A module, its AI features and any new add-ons sit inside the audited system boundary, not outside it.
3
Check the observation window and get a bridge letter
A Type II report covers a past period, often ending months before you read it. Ask for a bridge letter covering the gap between the report end date and today.
4
Confirm SSO on your protocol, and ask what it costs
SAML 2.0 or OIDC against your identity provider, enforced for all users including admins. Some vendors gate SSO behind higher tiers. Get the price in writing.
5
Ask about SCIM provisioning and deprovisioning
When someone leaves, does their access die with their directory account? Manual deprovisioning in a tool full of compensation data is a finding waiting to happen.
6
Pin down data residency in the order form
If EU residency matters, get the region named in the contract, not the sales deck. Ask where backups and support access live too, not just primary storage.
7
Pull the subprocessor list and check the AI vendors on it
Every AI feature adds a subprocessor, often a US model provider. Check retention terms, training-use terms and whether you can opt out per feature.
8
Ask for the latest penetration test summary
Annual third-party testing is the floor. Ask for the summary, the date, the scope and confirmation that criticals were remediated and retested.
9
Test RBAC depth against your real org chart
Can you restrict by entity, department, account range and scenario? Can a manager see their team's salaries but not their peers'? Test in the demo with your structure.
10
Review audit logging and export
Who changed which number, when, and can your SIEM ingest it? For SOX-relevant planning data, change history is not optional.
11
Check encryption claims and key management
AES-256 at rest and TLS 1.2 or higher in transit is standard. If you need BYOK, only a few vendors in this table document it. Ask early.
12
Agree breach notification and exit terms before signing
Notification windows, data return format and deletion certification belong in the DPA. Negotiating them after signature never goes well.

Frequently Asked Questions

As of September 2026, the vendors that publicly document a SOC 2 Type II (or SOC 2 Type 2) attestation on their own trust or security pages include Workday Adaptive Planning, Anaplan, Board, Pigment, Jedox, Planful, Prophix, Vena, Drivetrain, Abacum, Aleph and Cube. OneStream references SOC 1 and SOC 2 reporting in its service documentation without stating the type publicly, and Datarails states SOC 2 compliance without specifying the type. For those two, request the current reports in your security review.

A Type I report assesses whether controls were suitably designed at a single point in time. A Type II report tests whether those controls actually operated effectively over a period, usually 6 to 12 months. Type II is the meaningful one for vendor due diligence because it shows sustained operation, not a snapshot. If a vendor only offers Type I, ask when their Type II observation period ends.

No, they answer different questions. ISO 27001 certifies that the vendor runs a conforming information security management system. SOC 2 Type II is an auditor's attestation that specific controls operated effectively over a period, with the detail in the report. Mature vendors hold both. If a vendor has only one, that is workable, but you should read the underlying documentation rather than treat either badge as sufficient on its own.

Often yes. Compliance automation platforms have made SOC 2 Type II achievable for vendors with fewer than 100 employees, and Abacum, Aleph, Cube and Drivetrain all document current attestations. The honest difference is depth behind the badge: smaller security teams, shorter audit history, sometimes narrower report scope and fewer optional criteria. Review the actual report and the operational items, SSO enforcement, SCIM, subprocessors and pen test cadence, rather than assuming size equals risk in either direction.

Ask your sales contact for access to the trust center, or request the report directly under NDA. Vendors like Anaplan, Planful, Prophix, Pigment and Drivetrain run self-serve trust portals where reports are shared after a click-through agreement. If a vendor hesitates to share a report they claim to hold, treat that as a signal. Legitimate reports exist to be shown to prospects under NDA.

Five things move the risk needle most: SSO enforced for all users with SCIM provisioning, data residency that matches your regulatory footprint, the subprocessor list including AI model providers, recent third-party penetration test results, and role-based access control deep enough to segregate compensation and entity-level data. A vendor can hold a clean SOC 2 and still fail your requirements on any of these.

Pigment documents hosting in Frankfurt (europe-west3) or Oregon, plus a French sovereign option on S3NS SecNumCloud. Drivetrain documents Frankfurt or Virginia. Vena documents hubs in Canada, the US or EU cloud regions. Workday, Anaplan, Board, OneStream and Jedox operate multi-region clouds where EU hosting is contractual. For any vendor, name the region in the order form and ask where backups and support access sit.

No. A SOC 2 Type II report says an auditor tested the controls the vendor chose to include, over a defined past period, and reports the results including any exceptions. It says nothing about the months since the period ended, systems outside the scope boundary, or requirements the trust criteria never touch. It is a well-standardized starting point for your review, not the conclusion of it.

Continue Your Evaluation

Build a Shortlist Your Security Team Will Sign Off

Weigh these vendors against your own requirements, systems and compliance bar in the CFO Shortlist app.

Independent FP&A & EPM advisory for mid-market finance teams.

Helping CFOs, Controllers, and FP&A leaders choose, negotiate, and implement the right finance stack – without pay-to-play bias.

© 2026 CFO Shortlist. All rights reserved.

Independent, buyer-first EPM advisory.

No vendor compensation or pay-to-play sponsorships.