← Back to blog
Company UpdateJune 29, 2026

Valiance Health Begins Its SOC 2 Type II Journey

Valiance Health has started a SOC 2 Type II audit with Advantage Partners, with Vanta for continuous control monitoring. For a platform that handles clinical and claims data, trust is not a feature. It is the foundation.

Valiance Health has begun its SOC 2 Type II journey. We are working with Advantage Partners on the audit, and we use Vanta to monitor our controls continuously.

Why we are doing this

We build a healthcare data platform. It handles sensitive clinical and claims data from hospitals, insurers and administrators. For that kind of system, trust is not a feature you add later. It is the foundation you build on.

An enterprise client does not take a security promise on faith. They ask who audited it, against what criteria, and over what period. SOC 2 Type II answers exactly that. It does not test a snapshot. It tests whether controls actually operated over a period of months, and an independent auditor issues the opinion.

This step formalises the security and privacy controls our enterprise clients already rely on. It turns internal practice into evidence a third party has examined.

What SOC 2 Type II covers

The audit examines how we run the platform day to day, not just how we designed it:

  • Access control. Who can reach data, on what basis, and how we review that access.
  • Encryption. Protection of data in transit and at rest.
  • Change management. How code and infrastructure changes are reviewed and released.
  • Monitoring and incident response. How we detect problems and what we do about them.
  • Vendor and personnel controls. Who we depend on, and how our people are trained and offboarded.

Where we are today

SOC 2 Type II is not a one-day test. An auditor watches how controls operate over a defined observation window, and the report follows after that window closes. We are working through that process now.

We will publish the outcome when the report is issued.

Alongside SOC 2, our platform is built to align with HIPAA administrative, technical and physical safeguards, and with Malaysia's PDPA. We make BAAs available where they apply.

What this means for our clients

Hospitals and administrators trust us with data that describes real patients and real money. In the age of AI agents that read and act on that data, the question of who can see what, and who checked, gets sharper, not softer. Our answer is an independent audit and continuous monitoring, rather than a claim on a web page.

If your security team needs our documentation, start at our Security & Trust page. For policies, controls and subprocessor information, use the Trust Center linked from there.


This post expands on our announcement on LinkedIn. Our SOC 2 Type II journey is under way. We will report the outcome once the audit completes.