Announcing Onramp's SOC 2 Type I Report
Nick DeLozier | Chief Operating Officer
Onramp has received its SOC 2 Type I report. Advantage Partners, a trusted and independent CPA firm, examined the design of the security controls behind our Multi-Institution Custody solution as of June 11, 2026.
What a SOC 2 Type I is
SOC 2 is the AICPA's framework for how service organizations manage systems and data. A licensed CPA firm examines your controls (access, change management, vendor oversight, risk management, incident response, personnel procedures) and issues its professional opinion on whether they're suitably designed in accordance with the Trust Services Criteria. Type I evaluates design at a point in time; Type II tests operation over a period of months.
Why this matters to our clients
- Independent verification. Every company says its security is strong. This is different in kind; a licensed CPA firm examined our controls and staked its professional opinion on the result. Evidence, not assurances.
- It covers what you can't see. You've always been able to verify our custody architecture on-chain: Multi-Institution Custody distributes vault keys across three trusted key partners, so no single party can move client Bitcoin unilaterally. The operational layer behind the platform, the people, processes, and controls, was the part you had to take on our word. This report helps close that gap.
Why this matters now
The failures that have cost many people their Bitcoin haven’t been cryptographic in nature. They're operational breakdowns, code nobody re-examined, processes that never got tested, and they stay invisible until they aren't, in places no client can see from the outside. Recent events made that painfully concrete: a flaw sat in production firmware for years, and the people it hurt had done everything right.
An audit answers part of that problem, but a report is a snapshot, and threats don't hold still. This examination sits within a broader program and culture to ensure we are proactive about security and maintain our clients' trust. Onramp has and will continue to red-team our own systems and workflows continuously, testing them the way an attacker would, not the way a checklist reads. AI has changed the economics of that work: it lets us investigate far more paths through our code and infrastructure than manual review ever could, with our engineers validating every finding. And we apply the same skepticism to the AI itself; every tool we adopt undergoes a formal evaluation before it touches anything that matters. That discipline is how hidden flaws get found and corrected before they become headlines.
SOC 2 Type II and beyond
The Type II examination, testing whether these controls operate effectively over months rather than just on paper, has been underway for months, and we intend to renew it annually going forward.
And between reports, the monitoring doesn't stop. Our controls are continuously checked by automated compliance tooling through our partner Vanta, and the live status is published on our Trust Center. You don't have to wait for next year's report or take this post's word for it. Anyone can look today.
Verification shouldn't be a reaction to a headline. It should be a habit, and that's why we treat operational rigor as a security feature and why no milestone, this one included, is a finish line. As the threat landscape continues to evolve, so will Onramp.