Certifications
Last reviewed: September 3, 2026
Convesio’s platform and the data centers that host it are audited against the following standards.
Convesio platform
- PCI DSS 4.0.1 — Payment Card Industry Data Security Standard
- HIPAA — for HIPAA-eligible hosting plans (BAA available)
Data center / infrastructure certifications
- SSAE 21 / ISAE 3402 — SOC 1 Type 2
- AICPA Trust Services Criteria — SOC 2 Type 2 (AT-C 105/205)
- SOC 3
- ISO/IEC 27001:2022 — Information Security Management
- ISO 22301:2019 — Business Continuity Management
- PCI DSS 4.0.1
- NIST 800-53 Rev. 5 / FISMA
- HIPAA
Explanations
Below, you’ll find longer explanations of what these certifications are used for.
- SSAE 21 / ISAE 3402 SOC 1 Type 2
- A SOC 1 report covers a service provider’s processes and controls that could affect a client’s internal control over financial reporting (ICFR). A Type 2 report tests those controls over a period of time rather than at a single point. SSAE No. 21 replaced SSAE No. 18 for reports dated on or after 15 June 2022. An ISAE 3402 attestation is the international equivalent.
- It provides assurance to your customers that the service organization has adequate internal controls.
- An ISAE 3402 attestation including an audit report is regarded as a quality criterion for service providers that distinguishes them from competitors.
- SOC 2 Type 2 (AICPA Trust Services Criteria)
- SOC 2 examines controls relevant to security, availability, processing integrity, confidentiality, and privacy. It is performed under AT-C sections 105 and 205 against the AICPA Trust Services Criteria (2017, revised 2022) — not under the SOC 1 standard. A Type 2 report evaluates whether those controls operated effectively across the review period.
- The SOC 2 report examines the areas of security, availability, processing integrity and confidentiality. A secure organization:
- Protects data from unauthorized access
- Makes information and services readily available
- Runs systems that perform their functions correctly
- Keeps confidential information confidential
- ISO/IEC 27001:2022
- The international standard for information security management systems (ISMS). The 2022 revision restructured Annex A into four control themes and added 11 new controls covering areas such as threat intelligence, cloud security, and data masking. Organizations certified to the 2013 version were required to transition by 31 October 2025.
- PCI DSS 4.0.1
- The Payment Card Industry Data Security Standard governs any organization that stores, processes, or transmits cardholder data. Version 3.2.1 was retired on 31 March 2024; v4.0.1 (published June 2024) is the current standard, and all of v4.0’s future-dated requirements became mandatory on 31 March 2025. v4.0.1 places greater emphasis on continuous monitoring, multi-factor authentication, and customized implementation of controls.
- ISO 22301:2019
- A framework for business continuity management: identifying disruption risks, and building and testing incident response and recovery procedures so operations can resume quickly after an outage or incident
- HIPAA
- The Health Insurance Portability and Accountability Act sets the standard for protecting sensitive patient data. Organizations handling protected health information (PHI) must maintain administrative, physical, and technical safeguards. HHS issued a proposed overhaul of the HIPAA Security Rule in January 2025 (including mandatory MFA, encryption at rest and in transit, and asset inventories); it has not been finalized.
- NIST 800-53 Rev. 5
- A catalog of security and privacy controls for U.S. federal information systems. Revision 5 (September 2020) integrated privacy controls directly into the main control catalog and adopted outcome-based, technology-neutral language. Federal agencies and their contractors are required to comply; private organizations frequently adopt it as a security baseline.