Security

Passu completes SOC 2 Type I audit and independent penetration testing

Schuyler Fried

·

·

3 min read

At a glance

  • Passu completed a SOC 2 Type I examination covering the Security, Availability, and Confidentiality Trust Services Categories

  • An independent gray-box penetration testing evaluated app.passu.ai and its APIs

  • The test found no Critical- or High-severity findings; one Low-severity finding was remediated and retested

Passu, an AI credit research platform for institutional corporate credit teams, has completed a SOC 2 Type I examination and an independent gray-box penetration test. Together, the assessments provide point-in-time evidence about the design of Passu’s controls and the security posture of its web application and APIs.

Independent assurance for institutional research

Passu has completed independent assessments of both its control environment and application security. Its SOC 2 Type I report evaluated the design of controls across Security, Availability, and Confidentiality, while a separate penetration test evaluated app.passu.ai and its APIs. These assessments are meaningful diligence inputs, though no examination can guarantee that a system is risk-free.

Scope of the Type I examination

Thoropass Assurance issued Passu’s SOC 2 Type I report on January 28, 2026. The examination covered the Passu Platform as of January 16, 2026, across the Security, Availability, and Confidentiality Trust Services Categories. The report concluded that the controls described by Passu were suitably designed as of that date.

A foundation for ongoing assurance

A SOC 2 Type I examination evaluates whether controls are suitably designed at a specific point in time. A Type II examination evaluates whether controls operated effectively over a defined review period. Passu’s completed examination is Type I, with Type II expected to be completed over the coming six month period.

Independent application testing

From March 3 through March 6, 2026, Thoropass conducted a gray-box penetration test of app.passu.ai and its APIs. The assessment identified no Critical- or High-severity findings. One Low-severity finding was remediated, and the fix was validated through retesting.

Supporting your diligence process

Institutional credit teams evaluating AI credit research software need evidence about access controls, data protection, system availability, and application security. These assessments provide independent, point-in-time evidence about the controls and application reviewed; they do not eliminate security risk or guarantee future performance.

Security is ongoing work. Passu will continue strengthening its controls as the platform grows. Clients and qualified prospective customers can request current security documentation from the Passu team.

Schuyler Fried

Schuyler Fried

Co-founder & CTO

Schuyler leads product and engineering at Passu. He was previously head of engineering at AI real estate firm Zuma, backed by Andreesen Horowitz, and was a quantum computing scientist at Amazon and Rigetti Computing.