Big news: Pushwoosh is now SOC 2 Type 2 compliant
The report landed on September 22, 2026. Behind it is a 12-month examination, from August 1, 2025 to July 31, 2026, in which an independent auditor, ABV CPA, tested how Pushwoosh actually operated against the SOC 2 criteria for security, availability, and confidentiality. The opinion is unqualified, with no exceptions noted across every control tested.
In February 2025 we announced SOC 2 Type 1, which confirmed our security controls were properly designed. Type 2 confirms they actually worked, every day, for a full year. That distinction is the whole story, so here’s what it means in practice.
Type 1 vs Type 2: the difference in 1 analogy
Think of a bank vault.
Type 1 is the inspector looking at the blueprints and the finished vault on one particular day. The door is solid, the lock is the right kind, the alarm is wired. Everything is designed properly. That’s a point-in-time check.
Type 2 is the inspector reviewing a year of security footage. Did the door actually get locked every night? Did the alarm go off when it should have? Did the people with keys still work there? That’s what an auditor tests in a Type 2 examination: not whether controls exist, but whether they operated effectively, day after day, for the whole period.
To do that, the auditor at ABV CPA didn’t take our word for it. They sampled onboarding and offboarding tickets, access review minutes, merge requests, incident records, backup logs, and penetration test reports, then checked each one against the control it was supposed to prove.
What the auditor actually checked
The report runs to 50 pages and covers 3 trust services categories: security, availability, and confidentiality. Here’s a sample of what sits behind those words, in plain language.
- Who can touch your data, and for how long. Access to production is granted only with a recorded approval, reviewed every eight weeks, and revoked within 24 hours when someone leaves. Nobody outside Pushwoosh holds an account in our internal systems, and Pushwoosh never connects into yours.
- Every change gets a second pair of eyes. No engineer can approve their own code. Every change to the platform passes automated tests and peer review before it ships, and every release can be rolled back through the same pipeline.
- Your data never lands in a test environment. Development and testing run on synthetically generated data. Production data stays in production.
- Backups that were actually restored. Encrypted backups run daily, and during the audit period we performed a full point-in-time database recovery from those backups to prove they work.
- Someone tried to break in on purpose. An independent third party ran an external penetration test of the web application, public APIs, and website in July 2026.
🤖 One more thing worth spelling out. The audit scope covers the Pushwoosh platform, including ManyMoney AI and the MCP interface for AI-agent access. The AI features that build and optimize your campaigns are covered by the same controls as push, email, and every other channel.
What this means for a user
- Faster security reviews. If your procurement or security team asks for SOC 2, Type 2 is the version they usually mean. Having it ready shortens the vendor review from weeks of back-and-forth to a document exchange.
- Fewer questionnaires. Most of what a vendor security questionnaire asks (access control, change management, incident response, encryption, backups) is already answered in the report, with an auditor’s test results next to each item.
- 2 reports, not 1. Our ISO/IEC 27001:2022 certificates for both Pushwoosh legal entities were renewed in July 2026. Together with SOC 2 Type 2, that gives your compliance team both of the frameworks they’re most likely to ask for.
Request the report
The SOC 2 Type 2 report is shared under NDA or MNDA, which is standard practice for reports of this type. To get a copy, or the ISO 27001 certificates, contact our support team, and we’ll take it from there.
If you’re evaluating Pushwoosh and security is part of the conversation, bring your questions to the demo. We’d rather answer them upfront.
Related articles
View all