Last reviewed: August 2026

Resources

SOC 2 compliance

Approva is pursuing a SOC 2 Type II report. Readiness work is underway, no audit is engaged, and no report has been issued. Controls are designed against the Trust Services Criteria — security as the common criteria, along with availability, confidentiality, and processing integrity.

Current status

Approva is pursuing a SOC 2 Type II report and has not started the audit. Readiness work is underway, no audit firm is engaged, and no report — Type I or Type II — has been issued. Approva treats readiness as an ongoing program and publishes status here as milestones are reached, rather than naming a date it does not control. In the meantime, we can share our security posture and controls documentation under NDA — contact prashanth@approva.health.

Controls in scope

Security is the common criteria every SOC 2 engagement includes. On top of it, the program is designed to cover availability (uptime SLAs, incident response), confidentiality (PHI access controls, encryption), and processing integrity (change management, data validation). Logical access, vendor management, and risk assessment policies are documented as part of the same program. The privacy criterion is not in the current scope.

Supporting compliance

SOC 2 controls complement our HIPAA program. For a full overview of our security posture, including encryption standards and audit logging, see the security and compliance page.

FAQ

Frequently asked questions