Theori Acquires SOC 2 Type II Certification…Securing Global B2B Security Credibility
Theori announced on the 19th that it has obtained the 'SOC 2 (System and Organization Controls) Type II' report, a global security audit standard established by the American Institute of Certified Public Accountants (AICPA).
The audit was conducted through Sensiba, an independent global accounting and consulting firm, and received recognition of control effectiveness across three of the Trust Services Criteria required by SOC 2—△Security, △Availability, and △Confidentiality—and issued a final Attestation Report.
Unlike Type I, which only reviews the appropriateness of security procedure design, SOC 2 Type II verifies that security controls operated continuously in accordance with policies during the actual operational period.
Theori previously acquired ISO/IEC 27,001 (Information Security Management System) and ISO/IEC 27,017 (Cloud Security) simultaneously, and with this SOC 2 Type II acquisition, has now established an additional international security certification framework.
This certification applies across major SaaS product lines including the AI-based vulnerability diagnosis platform 'Xint' and LLM security solution 'αprism', and is reported to have demonstrated data stability meeting enterprise and financial sector customer requirements through external audits.
Theori plans to pursue CMMC (Cybersecurity Maturity Model Certification) acquisition within the year.
CMMC is a U.S. Department of Defense supply chain security standard and is considered one of the requirements for expanding global B2B partnerships.
Kwangsoon Park, CISO at Theori, stated, "An internal operational system that safely manages customer data is a core pillar of corporate security alongside offensive capabilities," and added, "Based on security control capabilities that meet global standards, we will establish ourselves as a trustworthy AI cybersecurity partner for enterprise customers both domestically and internationally."
Theori has provided security consulting to Google, Microsoft, Okta, and Samsung Electronics, and is recently expanding its business domain into AI-based penetration testing.














