Security

Enterprise finance demands enterprise-grade controls.

Bitwave is audited annually by EY for our SOC 1 Type II and SOC 2 Type II reports. Bitwave’s SOC 1 Type II and SOC 2 Type II reports provide customers and their auditors with independent assurance over the controls supporting our platform and operations.

Request SOC Reports

Built with Security-First Architecture

At Bitwave, security is foundational to how we build and operate our platform. We maintain rigorous internal controls and undergo independent annual audits to ensure our systems meet the highest standards for enterprise data security, availability, and integrity.

Bitwave is SOC 1 Type 2 and SOC 2 Type 2-compliant, reflecting our commitment to safeguarding sensitive financial and blockchain data for enterprise customers. Access to Bitwave’s SOC reports is available upon request and may be subject to confidentiality requirements.

Request SOC Reports
AICPA SOC for Service Organizations badge.

Independently Examined by a Big 4 Firm

Bitwave engages Ernst and Young, one of the world’s leading independent audit and assurance firms, to conduct its SOC 1 Type II and SOC 2 Type II examinations, and Bitwave's reports are available on request.

As Bitwave’s independent service auditor, EY evaluated the design and operating effectiveness of the controls covered by each examination over a defined period. The resulting reports provide customers, auditors, security teams, and risk professionals with detailed information for evaluating Bitwave’s control environment.

Bitwave SOC Report Details

SOC 1 Type II Financial reporting controls SOC 2 Type II Security and platform controls
Confidence in financial controls Confidence in platform controls
Examination firm Issued by EY Examination firm Issued by EY
Current report period January 1–December 31, 2025 Current report period January 1–December 31, 2025
Next report New report expected by the end of January 2027 Next report New report expected by the end of January 2027
What each report covers
A SOC 1 report evaluates controls at a service organization that may be relevant to its customers’ internal control over financial reporting. A SOC 2 report examines controls relevant to the applicable AICPA Trust Services Criteria, which can include security, availability, processing integrity, confidentiality, and privacy.
The report includes completeness and accuracy assurances and reviews the controls in place to achieve them. Bitwave’s SOC 2 Type II report provides customers with independent information about the design and operating effectiveness of the controls covered by the examination.
For Bitwave customers, this provides valuable assurance when evaluating technology that supports accounting, reconciliation, reporting, and other financial workflows. This provides valuable assurance when evaluating the controls supporting the security and operation of the Bitwave platform.

Fully compliant with the industry standard for trust.

The above aligns with the AICPA’s definitions of SOC 1 and SOC 2, two attestations building on each other for a comprehensive picture of trust.

SOC 1 addresses the integrity of the financial control environment. SOC 2 addresses the controls supporting the platform itself. Together, they give finance, audit, security, and risk teams a more complete basis for evaluating Bitwave.

Bitwave’s control environment is designed to support the teams responsible for evaluating and overseeing critical financial technology.

Built for public company financial operations

Financial institutions and global enterprises rely on Bitwave to connect onchain activity with their existing accounting, reporting, and operational systems.  
Bitwave undergoes independent examinations of the controls and security practices supporting our platform and business operations. Our SOC reports give customers, auditors, and risk teams detailed information and assurances of correctness that they can use during vendor assessments, financial audits, and security reviews.

Request a Copy of Bitwave SOC Reports