We’re pleased to share that Smart Merchandiser has completed SOC 2 Type II and SOC 3 examinations, both covering the AICPA Trust Services Criteria for Security. The examinations were conducted by independent auditor Johanson LLP and cover the period of April 9, 2026 through July 9, 2026. Both resulted in unqualified opinions.

This builds directly on the SOC 2 Type I attestation we achieved in April 2026.

What’s the difference, and why it matters

A SOC 2 Type I report evaluates whether security controls are suitably designed at a single point in time. A SOC 2 Type II report goes further: an independent auditor tests whether those controls actually operated effectively over a period of months. In short, Type I shows the controls are built correctly; Type II shows they work in practice, day after day.

For the security and procurement teams who evaluate Smart Merchandiser, that distinction is the difference between a promise and independently verified proof.

The SOC 3 report covers the same examination but is written as a general-use summary — so we can share it openly with customers, partners, and anyone assessing our security posture.

What this means for our customers

Enterprise retail and apparel brands trust Smart Merchandiser with a core part of their online storefront. These attestations give your security team third-party assurance that we protect your data with controls that are not only well-designed, but demonstrably effective over time.

Nothing changes in how you use Smart Merchandiser — this is about the rigor behind the scenes.

Access the reports

Our SOC 3 report is available through the Smart Merchandiser Trust Center. The SOC 2 Type II report is available to customers and prospective customers under NDA — contact us to request it.

Have questions about our security program? We’re happy to walk your team through it, contact us.

Share