Our Approach
Our Commitment
Why It Matters
SOC 2 Type II
audited annually since 2019
ISO 27001
cybersecurity framework baseline
1.25M
support tickets resolved
30
years earning client trust
1.

Layered Protection

Multiple defensive mechanisms work together so no single point of failure can compromise your systems. Physical safeguards, logical access controls, and automated monitoring all operate simultaneously.
2.

Automated & Continuous

Our security controls run around the clock. Automated detection, alerting, and response means threats are caught and contained quickly, regardless of the time of day or day of the year.
3.

Third-Party Accountability

We do not just say we are secure, we have proof. An independent auditing firm reviews our controls every year and issues a formal report. We have maintained SOC 2 Type II attestation for 7 years continuously.
4.

Continuously Improving

Security is never a checkbox we tick once. We hold quarterly security meetings to identify threat opportunities. We evolve our controls each year, incorporating tactical playbooks and novel techniques to stay ahead of emergent threats.

Why SOC 2 Type II Compliance?

Three men in business attire smiling, with the man in the middle holding a framed Certificate of Audit.

We voluntarily engage in a SOC 2 Type II audit each year because it's best practice. We prioritize this audit because it's the right thing to do. With a non-biased auditor, Net Friends is held accountable to strictly adhering to the best practice of our information technology framework and controls.

A third-party auditor challenges us to maintain rigorous records of how we adhere to our policies and procedures every day, all year long. Our auditor ensures we continue to evolve and adapt our controls to protect against emergent threats with tactical playbooks and novel techniques. They also critique and confirm the overall design of our controls.

You deserve an IT support company that is both continuously improving and constantly held accountable to the highest standards.

Annual SOC 2 Commitment

Since 2019, our SOC 2 Type II audits have been performed annually by KirkpatrickPrice. The auditor validates the (1) security, (2) availability, and (3) confidentiality of our internal systems and controls, as stipulated by the AICPA's Trust Services Criteria.

Our annual SOC 2 report is typically issued by April of each year. We're happy to make this report available upon request to our existing and prospective customers.

This continuous audit engagement (as opposed to a single point-in-time audit) is a stronger indicator of our IT excellence and commitment to remain vigilant and in top form. Read the announcement for our latest attestation:

Learn More
Certificate of Audit Graphic

Standards & Compliance — Audited, Certified, and Accountable

01

Compliance

SOC 2 Type II — Annual Audit

Annual Audit SOC 2 Type II is the gold standard for service organizations that manage customer data. Unlike a point-in-time assessment, this continuous audit spans the full year, validating that our security, availability, and confidentiality controls function as designed day after day. Performed by KirkpatrickPrice annually since 2019.

02

Framework

ISO 27001 Cybersecurity Framework

Net Friends uses the ISO 27001 framework to establish and maintain our information security baseline. Every policy and procedure is rigorously mapped to its standards, ensuring our risk-based controls are comprehensive and consistently applied across all physical and logical components of our business.

03

Trust

AICPA Trust Services Criteria

Our SOC 2 audit covers all three trust services criteria defined by the AICPA.

  • Security: The required common criteria, covering unauthorized access, disclosure, and system damage.
  • Availability: Ensuring our systems are reliably accessible for your operations.
  • Confidentiality: Protecting your intellectual property and business plans.

"It is our duty to provide customers with a non-biased, third-party confirmation of our information security practices."

John Snyder, CEO of Net Friends

Why This Matters

Every SOC 2 audit validates these three criteria as the foundation of our commitment to your business.
Security: Your information and systems are protected against unauthorized access, unauthorized disclosure, and damage that could compromise integrity, availability, or privacy.
Availability: Your IT support and critical systems stay available when you need them. We publish a Service Level Agreement and have invested heavily in our own business continuity.
Confidentiality: Information designated as confidential, your IP, business plans, sensitive records, is protected, properly maintained, and effectively disposed of on your behalf when the time comes.

"Congratulations Net Friends! Knowing the effort this takes year after year makes me glad to have you all as our IT partner. Inspiring!"

Garrett Cobb at CAHEC on our 7th SOC 2 Type II Attestation

SOC 2 Type II Audited badge

Ready for IT that has your back?

Let's have an honest conversation about your current security posture — no sales pitch, just genuine expert guidance.