Security
Arxova completed its SOC 2 Type 1 report
By JD Ramos, RN, Founder · October 2, 2026 · 4 min read
Arxova has completed a SOC 2 Type 1 report for the Security criteria. An independent CPA firm, Percilchofe CPA LLC, gave it a clean (unqualified) opinion. The report is dated September 23, 2026, and looks at our controls as of August 31, 2026.
I know that's a lot of letters and dates. I'm a nurse first, so I want to explain what it means in plain words, starting with you, the people whose records are in Arxova.
What is a SOC 2 report?
SOC 2 is a way for an outside auditor to check how a company protects the information it holds. The auditor is an independent CPA firm. It isn't part of the company, and it doesn't work for the company's customers.
The auditor looks at what are called controls. Those are the rules, tools, and habits that keep data safe. Who can log in to which systems. How changes get checked before they go live. What we do when something looks off.
When the work is done, the auditor writes a report and gives an opinion. A clean opinion, which auditors call "unqualified," means they didn't find problems serious enough to call out.
Our report covers the Security criteria. Security is the core part of SOC 2, and every report includes it.
What this means if your records are in Arxova
Your medical records and wearable data are some of the most private things you have. I've spent my career as a nurse being trusted with people's health information, and I don't take that lightly. You shouldn't have to take my word for how we protect yours.
A SOC 2 report means someone outside the company looked at how we built our protections and wrote down what they found. It's one more piece of proof, next to what we already share on our security page.
Nothing about how you use Arxova changes. Your records still sit in one place you control. You still decide where they go. ARIA still helps you understand your data, and it never diagnoses. And we don't sell your data. That hasn't changed, and it won't.
What this means for clinics and research partners
Before a clinic or research team can work with a company like ours, they usually have to review its security. A SOC 2 report is often a big part of that review.
If you're a clinic or research partner, you can request our SOC 2 Type 1 report under a non-disclosure agreement (NDA).
Type 1 vs Type 2, in plain words
There are two kinds of SOC 2 reports, and the difference matters.
- Type 1 checks whether the controls were designed well, at one point in time. Our report looks at August 31, 2026.
- Type 2 checks whether those same controls kept working over a period of months.
Here's how I think about it. Type 1 asks, "Is the plan sound?" Type 2 asks, "Did you follow the plan, day after day?"
Ours is a Type 1 report. I want to be upfront about that, because you deserve to know exactly what was checked. Type 2 is the next step, and it's underway.
What comes next
Two things are underway right now:
- SOC 2 Type 2. This will show whether our controls kept working over time, not just on one day.
- A penetration test. This is when security experts try to break in the way a real attacker would, so we can find and fix weak spots first.
I'll share updates here on The Pulse as each one is done.
How a small team got here
Arxova is bootstrapped, and we don't have a big compliance department. We had good help. Thank you to the team at Lowerplane, our compliance platform, for helping a small team get this done.
Request the report
If you're a clinic or research partner and want to review our SOC 2 Type 1 report, you can request access in the Arxova Trust Center, or email us at contact@arxova.health. We'll share it under an NDA. The Trust Center also shows the current status of our security controls.
If you want to see how Arxova protects your records today, start with our security page, or read who owns your medical records.
Thank you for trusting us with something this personal.
JD Ramos, RN
Founder, Arxova
SOC 2® is a registered trademark of the AICPA.
FAQ
Does Arxova have a SOC 2 report?
Yes. Arxova completed a SOC 2 Type 1 report for the Security criteria. An independent CPA firm, Percilchofe CPA LLC, gave it a clean (unqualified) opinion. The report is dated September 23, 2026, as of August 31, 2026.
What is the difference between SOC 2 Type 1 and Type 2?
A Type 1 report checks whether a company's security controls were designed well at one point in time. A Type 2 report checks whether those controls kept working over a period of months. Arxova's report is Type 1, and our Type 2 is underway.
What does SOC 2 mean for my health records in Arxova?
It means an independent auditor looked at how we designed the controls that protect your data. Nothing changes in how you use the app. You still decide where your records go, and Arxova does not sell your data.
Is SOC 2 a certification?
No. SOC 2 is an attestation report written by an independent CPA firm. It isn't a certificate. That's why we say Arxova completed a SOC 2 Type 1 report.
How can a clinic or research partner get Arxova's SOC 2 report?
Request access in the Arxova Trust Center at trust.arxova.health, or email contact@arxova.health. We share the SOC 2 Type 1 report with clinics and research partners under a non-disclosure agreement.
Get started
Arxova is free on iOS and Android. We do not sell your data.
Subscribe to The Pulse
This article is for general educational purposes only and is not medical advice. Speak with your own clinician about decisions related to your care. Arxova is a health data platform; participation in research is optional, opt-in, and revocable, and any compensation is provided by the partnering research institution through a licensed third-party payments partner. Arxova does not sell patient data and is not a data broker.