Security and compliance

Trust, made visible.

PickaxeTrust Center

Security you can examine.

Explore the security program documented in Pickaxe’s SOC 2 Type II examination, and request the full report for your organization’s review.

Request report by email
SOC 2

Independent examination

SOC 2 Type II

Auditor
KEN & CO. CPA LLC
Review period
September 12 – December 12, 2025
Report issued
January 5, 2026
Category examined
Security

What the examination covers

The auditor concluded that the system description was fairly presented and the controls were suitably designed and operated effectively during the review period, subject to the complementary controls expected of service providers and customers.

The examination addresses the Security category. Availability, Processing Integrity, Confidentiality, and Privacy were outside its scope. It does not provide assurance about the accuracy or reliability of AI outputs.

SOC 2 report, pp. 4–8 and 25. This examination covers the stated period; it is not a live assessment of today’s systems.

Security controls

Selected controls from the report. Open each topic for the documented practices and relevant audit qualifications.

Access managementRole-based access, access reviews, and protected production access.Read controls
  • Employee and contractor access is assigned by role under a least-privilege access model.
  • Control IAC-7 specifies at least quarterly reviews of access to in-scope systems, with required changes tracked to completion.
  • Remote production access requires authorized employees, multi-factor authentication, and an approved encrypted connection.

The system description mentions annual access reviews; the tested IAC-7 control specifies quarterly reviews. Employee offboarding was assessed for design and implementation, but could not be tested for operating effectiveness because there were no terminations during the audit period.

Report pp. 20–21, 58–59 · IAC-7, IAC-12, IAC-13

Encryption & backupsProtection for stored data, network traffic, and backups.Read controls
  • The report describes encryption of customer data at rest and in transit.
  • The auditor inspected SSL/TLS settings for confidential and sensitive data sent over public networks.
  • Backups are encrypted and restricted to key personnel. The IT team monitors completion and investigates backup exceptions.

Report pp. 15, 21, 56, 64 · CRY-4, NET-1

Secure developmentDocumented changes, independent review, and controlled releases.Read controls
  • Software and infrastructure changes must be documented, tested, reviewed, and approved before production implementation.
  • Development and testing environments are logically separated from production.
  • The auditor reviewed branch protection and sampled changes to verify review by someone other than the author and deployment by authorized personnel.

Report pp. 21–22, 74–75 · CHG-1, CHG-2, CHG-3

Monitoring & vulnerability managementIntrusion detection, vulnerability scans, and penetration testing.Read controls
  • Intrusion detection continuously monitors the network for potential security breaches.
  • External-facing systems receive host-based vulnerability scans at least quarterly; critical and high vulnerabilities are tracked to remediation.
  • Penetration testing is performed at least annually. Findings are addressed through remediation plans and the applicable internal SLAs.

Report pp. 23, 64, 75–76 · MON-1, IAO-2, VPM-1, VPM-2

People & vendor securityEmployee onboarding, security training, and vendor review.Read controls
  • New employees undergo background checks and sign confidentiality agreements.
  • Employees complete security awareness training during onboarding; management documents and tracks completion.
  • The vendor management program includes an inventory of critical vendors, security and privacy requirements, and at least annual reviews of critical vendors.

Report pp. 18, 37, 77–78 · HRS-1, SAT-1, TPM-1, TPM-2

Incident response & recoveryDocumented response procedures and exercises for recovery.Read controls
  • Security and privacy incident procedures are documented and communicated to authorized users.
  • Incident response and business continuity/disaster recovery plans are tested at least annually.
  • The response policy requires incidents to be logged, tracked, resolved, and communicated to relevant or affected parties.

No incidents were identified during the audit period, so incident handling had no event samples. For annual exercises that did not recur during the three-month period, the auditor inspected the most recent performance from the preceding 12 months.

Report pp. 72–74 · BCD-2, IRO-1, IRO-2, IRO-3

Service providers in the report

The report identifies these infrastructure, software, and advisory providers (pp. 15–17, 25). This inventory reflects the examination period and is not a current list of legal subprocessors. Provider controls were excluded from the auditor’s examination.

Service providers and their roles documented in the SOC 2 report
ProviderRole
Amazon Web ServicesCloud compute, networking, storage, and hosting; GuardDuty for threat detection.
Google CloudCloud compute, storage, networking, and application hosting; Cloud SDK for administration.
MongoDB AtlasManaged application database.
VercelFrontend hosting and deployment.
DatadogInfrastructure monitoring, application monitoring, logging, and alerts.
GitHubSource control, code review, and CI/CD workflows.
Google WorkspaceBusiness email, documents, storage, and collaboration.
WorkstreetSecurity governance and compliance advisory services, and penetration testing.
VantaCompliance evidence collection, control tracking, endpoint monitoring, and vendor management.

Resources

SOC 2 Type II report

The complete report includes the system description, auditor’s opinion, control tests, and results. Distribution is restricted to eligible customers, prospective customers, business partners, their practitioners, and regulators.

Request report by email

Opens your email app with a request to info@pickaxeproject.com. Include your company and review purpose. The Pickaxe team reviews access requests.

Frequently asked questions

What services were described?

The report describes Pickaxe’s no-code AI chatbot and form builders, knowledge-source connections, language-model integration, deployment and hosting, access and usage controls, monetization, and tool management (pp. 13–14).

Does the report certify HIPAA compliance or AI accuracy?

No. This examination addresses SOC 2 Security criteria for the stated review period. It is not a HIPAA certification, and the auditor explicitly excludes assurance on the accuracy and reliability of AI outputs (pp. 4–6, 25).

What responsibilities do customers have?

The report expects customers to meet contractual obligations, keep technical and administrative contacts current, supervise their personnel’s use of Pickaxe, maintain their own systems of record and continuity procedures, identify approvers for relevant configuration changes, and promptly report suspected security breaches or compromised accounts (p. 28).

Were all controls tested against actual events?

No. Some event-driven controls had no instances during the review period. For example, employee offboarding could not be tested for operating effectiveness because no employees were terminated. Incident handling was assessed through policies and management inquiry because no incidents were identified (pp. 59, 73–74).