Security built for institutional credit research

SOC 2 Type I and Type II examinations, independent penetration testing, and enterprise access controls support your security review

SOC 2 Type I and Type II examinations, independent penetration testing, and enterprise access controls support your security review

The controls behind the platform

Independently verified

SOC 2 Type I and Type II audited, with regular third-party penetration testing

Enterprise identity

SAML SSO centralizes authentication within your identity environment

Private infrastructure

Connect through AWS PrivateLink or deploy Passu within your VPC

Data protection

Data encrypted at rest and in transit throughout the platform

Fit Passu into your security architecture

Use your institution’s identity provider and choose the network and deployment configuration your team requires

Use your institution’s identity provider and choose the network and deployment configuration your team requires

SAML single sign-on

Centralize authentication within your institution’s identity environment through SAML SSO

Private connectivity

Connect to Passu from your VPC through AWS PrivateLink

Private VPC deployment

Deploy Passu within your private VPC when your infrastructure requirements call for a dedicated environment

Evidence for vendor-risk review

Passu maintains independent assurance reports and application-security testing for review during diligence

Passu maintains independent assurance reports and application-security testing for review during diligence

SOC 2 Type I and Type II examined

SOC 2 Type I and Type II examined

Passu completed SOC 2 Type I and Type II examinations in 2026. Type I evaluates control design at a point in time; Type II evaluates operating effectiveness over a review period.

Independent penetration testing

Independent gray-box penetration testing evaluated Passu’s web application and APIs. The assessment found no Critical- or High-severity findings; one Low-severity finding was remediated and retested.

Start your security review

Customers and qualified prospective customers can request current security documentation

Security questions, answered

Direct answers for technology, security, procurement, and vendor-risk teams evaluating Passu

Direct answers for technology, security, procurement, and vendor-risk teams evaluating Passu

Passu combines independently examined controls with enterprise identity, private connectivity, and encryption at rest and in transit. SOC 2 Type I and Type II examinations and independent penetration testing give your security team documented evidence for review.

Passu combines independently examined controls with enterprise identity, private connectivity, and encryption at rest and in transit. SOC 2 Type I and Type II examinations and independent penetration testing give your security team documented evidence for review.