Company News

MX8 Labs Achieves SOC 2 Type 1 Attestation

Megan Daniels
Megan DanielsCEO

If you've ever tried to get a research platform through a security review, you know the drill: the long questionnaire, the follow-up questions to the follow-up questions, the deal sitting in procurement while everyone waits. Your security team isn't being difficult. They just have no independent evidence to go on.

Now they do.

MX8 Labs is SOC 2 Type 1 attested, following an independent audit by Prescient Assurance, a licensed CPA firm specializing in security attestation for B2B SaaS companies.

SOC 2 Type 1 — Tested and Attested by Prescient Assurance

What an Auditor Just Put on the Record

SOC 2 is the AICPA's framework for how service organizations protect customer data. It isn't a certificate you buy. It's a licensed auditor's written opinion that your security controls are suitably designed and in place. Prescient Assurance examined ours against the AICPA's Trust Services Criteria, covering access control, change management, incident response, and vendor management.

Type 1 covers the design of those controls at a point in time. Type 2 examines how they operate over a period of months, and we're already collecting evidence for ours.

From Questionnaire to Evidence

Every study on MX8 Labs carries data worth protecting: respondent answers, first-party customer lists, unreleased creative, and the findings. Until now, the platform's security story was ours to tell. Now your security team can read an independent auditor's report instead of a questionnaire we filled in ourselves. Reviews get shorter, and deals spend less time stuck in procurement.

Built In, Not Bolted On

The audit examined controls behind commitments the platform already makes: fine-grained permissions over who sees what, regional data residency, privacy compliance with consent management and PII scrubbing, and encryption in transit and at rest. None of it was built for the audit. The auditor examined the platform as it runs every day.

What You Need to Do

If you're already running studies on MX8 Labs, nothing. There's no migration, no new settings, no change to how the platform works. The attestation covers the platform you're using today. If your compliance team keeps a vendor file on us, the report is the document they'll want in it, and requesting a copy takes an email.

If you're evaluating MX8 Labs, send your security team to the trust portal before they send you the questionnaire. It answers most of it.

Getting the Report

Our security documentation and current certification status live at trust.mx8labs.com. The full SOC 2 report is a restricted-use document, so we share it under NDA. Request it through the trust portal or from your MX8 Labs contact.

The Type 2 examination is underway, and you'll read about it here when it lands.