Phoebus Software Renewed SOC 2 Type II Attestation
The independent assessment verified 89 security and availability controls through July 2026.
Updated on Sept. 28, 2026 in Software

Live Poll
Do you trust financial technology firms more when they maintain independent security attestation?
Phoebus Software completed an independent SOC 2 Type II assessment covering the period from August 1, 2025, to July 31, 2026. This renewal confirms that the firm maintained effective security, availability, and confidentiality protocols for its financial technology stack.
Why it matters
Maintaining this attestation supports ongoing client due diligence and supplier assurance requirements for the financial sector. The firm currently supports more than £120bn in assets across its client base in the UK and Ireland.
KPMG evaluated 89 unique controls relating to security, availability, and confidentiality across the company's platform. While the firm successfully validated these measures, auditors noted two minor exceptions during the twelve-month reporting cycle.
The players
Phoebus Software
A financial technology provider supporting over £120bn in assets for more than 25 clients across the UK and Ireland.
KPMG
A global professional services firm that conducted the independent assessment of the company's internal controls.
The details
The SOC 2 Type II audit serves as an independent evaluation of how a service organization manages data. KPMG tested the effectiveness of 89 controls—specific operational procedures used to mitigate risk—against established industry standards for security and systems availability. Phoebus Software, which already holds the ISO/IEC 27001:2022 certification for information security management, underwent this testing to verify that its operational design consistently protects its financial services architecture.
Timeline
2023: Phoebus Software first achieved SOC 2 Type II attestation.
August 1, 2025 - July 31, 2026: The reporting period for the audit.
The Tech Race
This renewal complements the firm's existing ISO/IEC 27001:2022 certification by providing a periodic, independent performance review of its security controls. It marks the continuation of a multi-year audit cycle that began with the company's first SOC 2 achievement in 2023.
Clients using the Phoebus platform gain updated assurance that the infrastructure supporting their financial assets remains compliant with standard security frameworks. The attestation provides the documentation necessary for existing firms to maintain their own regulatory and audit-ready status.
The takeaway
Reliable compliance reporting is a baseline requirement for financial software providers managing large-scale asset pools. Stakeholders should track the firm's next scheduled audit cycle to monitor for the resolution of the two exceptions identified in this period.
Further reading
For broader trends in enterprise security compliance, explore our Software coverage.
Source note: This article includes information reported by FinTech Global.
Live Poll
Do you trust financial technology firms more when they maintain independent security attestation?






