
Fintech
Forest
Forest is SOC 2 Type II
Maxence Bruyas
We're proud to announce that Forest is officially SOC 2 Type II. Forest was built for regulated data; the audit confirms we run the company the way we built it.
Prescient Assurance LLC issued Forest an unqualified SOC 2 Type II opinion on July 24, 2026, on Security, tested from February 1 to May 31, 2026. Letter and report are on the Trust Center.
Equally as interesting is why we sought the attestation:
Forest was built for regulated data
We hold none of it. The Forest backend runs inside your infrastructure, next to your databases. Our control plane carries configuration and metadata. Data reaches a provider only at the moment its service is called, and the response is logged back to the case.
That was the architecture at launch, years before DORA. Not a compliance move: the only way to build for an ops team that cannot copy its records into someone else’s cloud.
The architecture only answers half the question
The other half is us. Who at Forest can reach production. What happens between a commit and a deploy. What we do in the first hour of an incident. Architecture has no opinion on any of it. Process does, and only process someone outside the company has tested.
That is what the audit was for. Not a badge.
Which is why we took our time
Default control sets are cheap and describe nobody. Ours are written against what Forest actually is: a backend inside customer infrastructure, a deliberately small control plane, a remote-first team with no office network to hide behind.
Same logic on tooling. Zero trust, not perimeter: JumpCloud for identity and device posture, Cloudflare for network and application access, SentinelOne for endpoint detection and response. Access is decided per request. Being on a network grants nothing.
What your risk team gets
Better evidence under an assessment you still have to make yourself. DORA and the EBA outsourcing guidelines don’t let any vendor’s report do that for you. What changes is what sits underneath: a tested control set over a defined window instead of a questionnaire we filled in ourselves.
Vendor file: unqualified opinion, Security scope, February to May 2026 period.
Questionnaire: most of the access control, change management and monitoring answers are already in the report.
Full report: available on request. The attestation letter clears most reviews on its own.
Both answers in one place
Our Trust Center at trust.forest.app carries the letter, the control list and the security documentation. And the auditor’s report, [Jul26] Auditor’s SOC 2 Type 2 (Prescient), is just one request away.
Nothing in this audit changed how Forest handles your data. It was never going to. The architecture has kept your records inside your own infrastructure since the first line of the product; the report is an outside firm confirming we run the company the way we built it.
Forest runs regulated operations, human and agent, on your own infrastructure with the audit trail your regulator expects. Building this? forest.app.
