August 14th, 2026

Lamatic.ai Renews SOC 2 Type 2

Lamatic.ai has successfully renewed its SOC 2 Type 2 certification, completing its second consecutive annual examination conducted by Prescient Assurance LLC (Nashville, TN) for the period April 1 – July 15, 2026.

Renewal matters. A single SOC 2 report tells you our controls were designed correctly. A renewed report tells you they kept working through infrastructure changes, team changes, and a significantly expanded scope. This cycle is our most comprehensive yet: we expanded coverage to three Trust Service Criteria, overhauled our infrastructure stack, and brought in best-in-class compliance partners to make the audit process more rigorous and repeatable.


Three Trust Service Criteria, Now Verified

Our previous certification covered Security alone. This renewal adds Confidentiality and Availability, two criteria that enterprise and regulated-industry customers consistently ask about in procurement.

Security: Controls protect the Lamatic platform against unauthorized access, threats, and vulnerabilities. This includes role-based access control, MFA enforcement, annual penetration testing, and continuous automated vulnerability scanning.

Confidentiality:Β Customer data and information subject to confidentiality agreements are handled, stored, and disposed of in accordance with documented policies. Employees and contractors are bound by NDAs, and data access is governed by least-privilege principles reviewed quarterly.

Availability: The platform is monitored around the clock with real-time dashboards and alerting. Incident response procedures are documented and tested. Backups are encrypted at rest and maintained across redundant providers.

An independent auditor reviewed our controls and confirmed they operated effectively throughout the entire audit period, not just at a point in time.

You can view our real-time compliance posture at trust.lamatic.ai.


New Stack Vendors: Hardened for Performance and Security

This renewal cycle coincided with meaningful upgrades to the Lamatic infrastructure stack. Several new vendors were brought in specifically to raise the performance and security bar, and all were fully in scope for the auditor's testing.

  • DigitalOcean (primary cloud): All production workloads and managed databases now run on DigitalOcean with tenant-isolated infrastructure as a core design principle, replacing GCP as the primary provider.

  • Aikido Security: Consolidated all security scanning into a single platform covering SAST, SCA, DAST, container scanning, IaC scanning, and developer device monitoring. Replaced separate Deepsource and Snyk tools.

  • Grafana: Centralized observability across all infrastructure components, aggregating metrics, logs, and traces with real-time dashboards and incident alerting.

  • ClickHouse: High-performance analytics database for platform data, replacing legacy infrastructure.

  • Weaviate: Vector database powering AI agent memory, fully in-scope for data security and availability controls.

  • Cloudflare WAF/CDN: Network-layer protection with DDoS mitigation across all production endpoints.

Controls were assessed against the live system with all new vendors in place, not a pre-change snapshot.


Our Security and Compliance Partners

Building a rigorous compliance program as a lean team requires the right partners. Here's who we worked with and what role each played:

Vanta: Compliance automation and continuous control monitoring. Vanta powers our ISMS, tracks evidence collection across all in-scope systems, and keeps our control posture current between audits. It's the operational backbone that makes ongoing compliance sustainable, not a once-a-year scramble. Our live trust page at trust.lamatic.ai is powered by Vanta and shows real-time control status to anyone who needs it.

Aikido Security: Our security testing platform. Beyond continuous scanning, Aikido monitors developer devices and flags vulnerabilities across our entire codebase and infrastructure in real time. It gave our auditors a live, verifiable evidence trail for security controls rather than point-in-time screenshots. You can request our Aikido security report directly at aikido.dev/audit-report/lamatic.

Prescient Assurance LLC: Our independent SOC 2 auditor, based in Nashville, TN. Prescient conducted the Type 2 examination in accordance with AICPA attestation standards, reviewing both the design and operating effectiveness of our controls over the full audit period.


How We Used AI Agents to Run a More Rigorous Audit

As a platform built for AI agents, we practiced what we preach. This audit cycle was the first time we systematically used agents to accelerate and strengthen the internal audit process.

We deployed agents to cross-reference our SOC 2 system description against live Notion policy documents, flagging inconsistencies between attested controls and actual configurations before the auditor ever saw them. Agents reviewed the testing matrix for internally contradictory findings, tracked the status of every open non-conformity across our compliance database, and maintained real-time updates to our Internal Audit Report, Statement of Applicability, and System Description as the audit progressed.

The result: Our internal audit team caught and resolved gaps that would typically surface only during fieldwork, reducing back-and-forth with Prescient Assurance and compressing the overall audit timeline. This is the same capability we're building into the Lamatic platform for our customers.


Ready to Evaluate Lamatic

If you're evaluating Lamatic for an enterprise or regulated environment, here's how to access our security documentation:

  • Real-time compliance status: trust.lamatic.ai shows our live control posture, updated continuously.

  • Aikido security report: Request our automated security scan report at aikido.dev/audit-report/lamatic. No NDA required.

  • SOC 2 Type 2 report: The full Prescient Assurance report (testing matrix, subservice org disclosures, management assertion) is available under NDA. Reach out at hello@lamatic.ai or contact your account team directly.


Lamatic.ai is a product of Dinner Technologies, Inc. Prescient Assurance LLC conducted the SOC 2 Type 2 examination in accordance with the AICPA's attestation standards.