SOC 1 Type II Certified: Cleeng Passes First Audit With Zero Exceptions

Company News | Jamini Rath |
Post image

Cleeng has achieved SOC 1 Type II certification, with zero exceptions across all 38 controls tested.

Independent auditors Johanson Group spent nine months examining how Cleeng handles the money that flows through our platform on behalf of our clients. Their verdict? A clean bill of financial health.

What SOC 1 certification is

Our clients collect subscriber revenue through Cleeng, and that revenue ends up in their own financial statements. When their auditors sign off on those statements, they need to be confident that the system processing that revenue – ours – is properly controlled. A SOC 1 report is how we demonstrate that, rather than simply asking clients to take our word for it.

There are two types of SOC 1 reports, and the difference matters:

  • Type I checks whether the right controls exist and are designed properly – a snapshot on a single day.
  • Type II, which Cleeng now holds, checks whether those controls actually worked, every day, over an extended period.

What SOC 1 certification means for Cleeng and its clients

  • Clients can close their books with confidence. Streaming, broadcasting, and D2C clients running subscriber revenue through Cleeng can now hand their own auditors a report instead of an assurance. Cleeng stops being an open question in someone else's year-end audit.

  • Enterprise deals move faster. Security and procurement review is typically where larger deals slow down. A clean SOC 1 Type II is one of the strongest answers we can put on the table, and it's ready before the question is even asked.

  • It proves the operating model holds up. This isn't a documentation exercise; an independent firm tested whether our day-to-day practice matched what we say we do, for nine months straight, with zero exceptions.

What it took

Cleeng designed and operationalized a formal internal controls framework covering every part of the business that touches subscriber revenue – from sign-up to payout. Each control was built into daily practice and evidenced monthly so an independent auditor could test it.

The result was seven control objectives spanning 38 individual controls:

Control objective Controls What it covers
Business operation 6

Subscription sign-up, customer data capture and processing

Transaction processing 3

Billing and revenue recorded completely and accurately

Payouts and settlements 4

Merchant funds reconciled and paid to the right party

Change management 3

Changes authorized, tested and approved before release

Information security and access 7

Least-privilege access to programs, data and systems

Computer operations 9

Processing executed completely, errors tracked and resolved

Risk assessment and mitigation 6

Risks identified, analyzed, and addressed in operations

 

All 38 passed.

Cleeng's SOC 1 Type II certification joins its existing SOC 2 Type II certification, giving clients independent assurance on both the security of subscriber data and the integrity of the financial processes handling their revenue.