Good security is easy to claim and harder to prove.
Frontify recently completed its first SOC 2 Type 2 audit — an independent examination that evaluates whether an organization's security controls are not only well designed but also operate effectively over a defined period. Businesses are evaluated against the American Institute of Certified Public Accountants' (AICPA) Trust Services Criteria (TSC): security, availability, processing integrity, confidentiality, and privacy.
We talked to Fleur-Catherine Glogger — the Manager, Information Security Governance & Deputy CISO at Frontify — about what the audit involved, what changes for customers, and why "you can't have a successful security program with just a security team."
Fleur, let’s start at the beginning: Why did Frontify decide to pursue SOC 2 Type 2?
Security has been at the core of Frontify since day one. Over the years, we've built a strong foundation through frameworks like ISO 27001, as well as more specialized ones like TISAX (Trusted Information Security Assessment Exchange) and Cyber Essentials. We've never treated compliance as collecting badges. Every framework is an opportunity to improve how we operate.
As we grew and started working more with enterprise customers, particularly in the United States, SOC 2 became one of the most common requests from customer security teams, so it was a combination of our own ambition to keep improving and the expectations of our customers.
For anyone who's new to the topic, what actually is SOC 2 Type 2?
Contrary to popular belief, SOC 2 isn't a certification. It's an attestation. This means that an independent auditor issues a detailed audit report describing their findings, rather than awarding a certificate.
SOC 2 Type 2 is an independent audit that shows a company doesn't just have good processes on paper, but consistently follows them. The difference between Type 1 and Type 2 is simple. Type 1 says: Today, your controls look good. Type 2 says: We watched your controls operate successfully over a set period. That's why Type 2 carries more weight.
What’s important to know is that companies choose the observation period: 3, 6, or 12 months. We started with 3 months because we wanted the program up and running, and we'll extend it to 12 months going forward. The report then states that over a defined window, the company operated its security controls successfully.
What does earning SOC 2 Type 2 actually involve?
SOC 2 is a catalog of controls, and you need to show how your processes meet them. We used Vanta, a compliance automation platform, and connected our systems to it. You put everything in, and an auditing team works in the background.
Early on, they were more or less silent watchers. Toward the middle and end, they were actively going onto the platform and checking whether we'd patched vulnerabilities within our service-level agreements, whether we'd run awareness training, and whether we do access reviews. It's a big team effort across multiple teams.
Were you confident it would work out?
It was a mix, honestly. SOC 2 focuses heavily on the technical side, and because our systems are connected to Vanta, everything is observed in real time. With an ISO audit, they ask for specific examples. With Vanta, we were effectively being watched 24/7.
On the one hand, we knew our security program was stable. On the other hand, you're always a little nervous because auditors vary. Some are stricter than others.
What does the certification mean for customers and prospects?
Nothing changes about the product or the services we offer. I also don't think it materially changes how customers view our security, because we've been investing in security and demonstrating it for years. We already have a lot of enterprise customers who trust us.
Where I hope customers and prospects see a difference is in procurement. Enterprise security reviews can take weeks or months, and the same questions come up over and over. With this report, we can point to the controls we have in place and show they're operating effectively. If that shortens the conversation for security teams on both sides and for our commercial teams, everyone gets to focus on what actually matters, which is strengthening security.
The fact that existing customers didn't notice anything is a good sign. We didn't have to rebuild anything or change our processes.
What's next for security at Frontify?
We never treat a framework as a point-in-time activity that you complete and then forget until next year's audit. Every framework we introduce is there so we can keep improving, which is the goal of all of them.
For SOC 2 specifically, we'll extend the observation period from three months to a year, and we'll expand the scope where it makes sense. More broadly, now that we've used Vanta for the first time, our goal is to make security less manual. Compliance still involves a lot of collecting screenshots and evidence. We're investing in automation and AI to make it a continuous effort, so we can focus on what we do best, which is securing the company.
What does this report mean to you personally?
I've been at Frontify for almost six and a half years, and I was the second person in the security team. I'm proud of the achievement, but I'm even prouder of how far we've come.
SOC 2 reflects something I've always believed: You can't have a successful security program with just a security team. You need engineering, DevOps, people teams, and commercial teams. Everyone in a company owns a piece of security. This is another example of what's possible when the whole company works together. And that’s why I also want to thank every employee at Frontify: Some people worked more directly on this, but we needed everyone — we wouldn’t be successful without the support of the entire company.
The SOC 2 Type 2 report is available upon request through our Trust Center. If you want to know more about security at Frontify, contact security@frontify.com.



