
1. The report
Our SOC 2 Type II observation window closed in December and the report is now available, with zero exceptions across all five trust services criteria. Type II matters more than Type I here: it describes how the controls behaved over months, not whether they existed on one day.
2. What changed in the trust center
The trust center now publishes the artifacts rather than describing them. Sub-processors, the current report, penetration test summaries and our incident history are all reachable without a sales conversation and without an NDA for the summary tier.
3. Why we publish it this way
We ask vendors to make evidence retrievable instead of requestable. It would be difficult to keep asking that while our own report sat behind a form.
4. Requesting the full report
Customers and prospects under NDA can pull the full report directly from the trust center. It re-issues annually, and the page shows the observation window so nobody has to guess how fresh it is.

About Zoe Harrington
Zoe is the Chief Security Officer at Urengi. Formerly a security infrastructure architect at a large observability vendor and a lead auditor for global tech frameworks, she writes extensively on vendor risk models and zero-trust procurement cycles.





