
AICPA SOC 3 Report now available
Examination period March 1, 2025 to February 28, 2026
Issued by Thoropass Assurance, Arlington, VA
Three Trust Services Criteria, independently examined
Cybele Software's controls were evaluated against the AICPA's 2017 Trust Services Criteria for Security, Availability, and Confidentiality throughout the entire 12-month examination period.
Security
Cybele protects customer data from security breaches through technological controls.
Availability
Thinfinity Products are kept available and recoverable through tested operational controls.
Confidentiality
Confidential customer data is classified, encrypted, and disclosed only when authorized.
Audited at the Cybele control plane
These attestations apply to Cybele Software's own organization — our development, build, deployment, and support processes for the Thinfinity Products.
SOC 2 Type II
Operational effectiveness audit
Confidential, detailed report under NDA. Available to enterprise customers and prospects on request.
SOC 3
Public attestation report
Freely distributable summary. No NDA required. Use it in your RFP responses and vendor questionnaires.
Cloud Build Partner
Marketplace listed, Co-sell ready
Oracle Cloud Infrastructure
Our primary cloud platform. Thinfinity is offered through the Oracle Cloud Marketplace and runs natively on OCI compute, networking, and Kubernetes (OKE) across global regions.
SOC 1
Financial controls
SOC 2 Type 2
Trust Services Criteria
SOC 3
Public attestation
ISO 27001
Information Security Management
ISO 27017
Cloud security controls
ISO 27018
Cloud PII protection
PCI DSS
Payment card data
HIPAA
U.S. health data
FedRAMP
U.S. federal cloud
GDPR
EU data protection
BSI C5
German cloud security
CSA STAR
Cloud Security Alliance
Technology Partner
EU sovereign cloud, No CLOUD Act exposure
IONOS CLOUD
Our European sovereignty partner. German-headquartered, GDPR-native, operated entirely within EU jurisdiction. Recommended for customers with EU data residency and digital sovereignty requirements.
ISO 27001
Information Security Management System certification for IONOS data centers
BSI C5 (Type 1)
Germany's Cloud Computing Compliance Criteria Catalogue for Compute Engine, Cloud Cubes, S3
BSI IT-Grundschutz
German federal IT baseline protection — first cloud provider to hold both this and C5
GDPR
EU General Data Protection Regulation — data processed and stored entirely within the EU
PCI DSS
Payment Card Industry Data Security Standard support for hosted environments
ISO 27017 / 27018
Cloud-specific information security and PII protection in the cloud
Subservice Organization
Microsoft Azure
Named as a subservice organization in our SOC 3 report. Azure provides infrastructure and data hosting services that support Cybele's own development, build, and deployment environment for the Thinfinity Products.
SOC 1
Financial controls
SOC 2 Type 2
Trust Services Criteria
SOC 3
Public attestation
ISO 27001
Information Security Management
ISO 27701
Privacy Information Management
ISO 27017
Cloud security controls
ISO 27018
Cloud PII protection
PCI DSS
Payment card data
HIPAA / HITRUST
U.S. health data
FedRAMP High
U.S. federal cloud
GDPR
EU data protection
BSI C5
German cloud security
What you get, by responsibility layer
Thinfinity is customer-deployed: you keep control of where it runs and what data it touches. Compliance is built up in three layers.
Customer-managed
Cybele-attested · SOC 2 Type II + SOC 3
Provider-attested · OCI or IONOS
Need the full report?
Three ways to get what you need for vendor reviews, RFPs, and procurement.
Download the SOC 3 report
Public attestation. No NDA required.
Request the SOC 2 Type II
Detailed audit report under mutual NDA. Routed through your account team.
Talk to compliance
Vendor questionnaires, custom scoping, or on-prem deployment review.