In September 2026, Cleeng received an Independent Service Auditor's Report for SOC 1 Type II, with no exceptions across all 38 controls in scope.
A SOC 1 report covers the controls at Cleeng that are relevant to your internal control over financial reporting: the systems that process subscriber transactions, record revenue, and settle funds to you. Because the revenue you collect through Cleeng appears in your financial statements, your auditors need evidence that the systems processing it are properly controlled. The SOC 1 report gives them independently tested evidence instead of an assurance from Cleeng.
Key Highlights
- Report type: There are two types of SOC 1 reports. A Type I report assesses whether controls are suitably designed and in place on a single date. A Type II report also tests whether those controls operated effectively throughout a defined period. Cleeng's report is Type II.
- Independent assessment: The examination was performed by Johanson Group, an independent third-party audit firm.
- Scope: 38 controls grouped into seven control objectives, covering the subscriber lifecycle from sign-up through to merchant payout.
- Test results: All 38 controls were tested, and no exceptions were reported.
Control Objectives in Scope
| Control objective | Number of controls | What it covers |
|---|---|---|
| Business operation | 6 | Subscription sign-up, customer data capture and processing |
| Transaction processing | 3 | Billing and revenue recorded completely and accurately |
| Payouts and settlements | 4 | Merchant funds reconciled and paid to the right party |
| Change management | 3 | Changes authorized, tested and approved before release |
| Information security and access | 7 | Least-privilege access to programs, data and systems |
| Computer operations | 9 | Processing executed completely, errors tracked and resolved |
| Risk assessment and mitigation | 6 | Risks identified, analyzed, and addressed in operations |
Implications for Cleeng's Clients
- Audit evidence: During your year-end close, you can provide your external auditor with an independent report on the controls Cleeng operates on your behalf.
- Assurance over a period, not a single date: Because this is a Type II report, the auditor tested whether each control operated effectively throughout the audit period.
- Support for your compliance obligations: The report supports your own financial reporting and audit requirements when you use Cleeng to collect and settle subscription revenue.
Requesting the Report
The full report, including the complete list of controls and the auditor's test result for each, is available to Cleeng clients on request. To request a copy, contact your Cleeng Account Manager or our Support Team. The report is shared under a non-disclosure agreement.
Frequently Asked Questions (FAQs)
Do I need Cleeng's SOC 1 report, the SOC 2 report, or both?
It depends. Your finance team and external auditors will want the SOC 1 report, because it covers the controls over the revenue that flows into your financial statements. Your security, risk, or procurement teams will usually want the SOC 2 report, because it covers data security, availability, processing integrity, confidentiality, and privacy. Many organizations request both.