
Jetstream Solutions has completed its SOC 2 Type 2 examination. The audit was performed by A-LIGN, an independent CPA firm and one of the largest issuers of SOC 2 reports, and covered the period from April 1 through June 30, 2026. The report was issued on September 9, 2026.
The short version: every control A-LIGN tested came back with no exceptions noted, and the report carries an unqualified opinion.
SOC 2 is a framework from the AICPA for reporting on how a service provider protects customer data. There are two kinds of report. A Type 1 report looks at whether controls are designed properly at a single point in time. A Type 2 report goes further: an independent auditor tests whether those controls actually operated, day in and day out, across a review period. We went straight to Type 2.
Our report covers the Security trust services category, which is the foundation every SOC 2 report is built on. It includes the controls that security teams ask about most:
Access control and multi-factor authentication for the systems that touch customer data
Encryption of data in transit and at rest
Change management for every production release
Vulnerability scanning and patching
Centralized logging, monitoring, and alerting
Incident response and customer notification
Backups and disaster recovery testing
Risk assessment and vendor management
We don't store your Salesforce data. Jetstream connects to your Salesforce org using your own credentials and your own permissions. Your record data is not stored by Jetstream. We keep encrypted connection credentials and the metadata needed to run the app, and that's it. That has always been the design, and now an independent auditor has reviewed it.
Security reviews go faster. If your security or procurement team needs to evaluate Jetstream, the SOC 2 report answers most of a vendor questionnaire up front. Combined with SSO support, our Data Processing Agreement, and our published list of sub-processors, we can get through a security review faster.
Small company, real controls. Jetstream is a small company, and the report says so plainly. Rather than paper over that, we built the security program around it: automated enforcement wherever a manual check would depend on one person, independent third-party reviews of access and controls, and an auditor who tested all of it.
The full report is available under NDA to current customers and to prospects evaluating Jetstream's paid offerings.
For an overview of how Jetstream handles data, see our Privacy & Security page.
SOC 2 isn't a one-time event. The controls keep running, and A-LIGN will examine them again each year, with the next report covering a full twelve-month period. If you have questions about our security program, or a requirement we haven't covered yet, I'd like to hear from you at [email protected].
Thanks to everyone who has trusted Jetstream with their Salesforce work. This is a big milestone for us and one I'm proud of.