FinTech provider Phoebus Software renews SOC 2 Type II attestation

FinTech provider Phoebus Software renews SOC 2 Type II attestation

Phoebus Software has renewed its SOC 2 Type II attestation following an independent assessment by KPMG, with the review covering 89 controls across a 12-month reporting period.

The assessment covered the period from 1 August 2025 to 31 July 2026 and found that Phoebus Software’s controls were appropriately designed and operated effectively throughout the period.

The company first achieved SOC 2 Type II attestation in 2023, with the latest assessment marking its fourth consecutive year of compliance. The 2026 assessment tested 89 unique controls, making it one of the company’s largest assurance exercises to date. Two minor exceptions were identified during the reporting period.

SOC 2 Type II is an assurance framework used to assess how organisations manage controls relating to areas including security, availability and confidentiality. For financial services technology providers, such assessments can support client due diligence and supplier assurance requirements.

Phoebus Software also holds ISO/IEC 27001:2022 certification, an international standard for information security management systems.The company provides technology for mortgages, savings, lending and deposits, supporting multi-channel, multi-product and multi-currency operations. Its platform covers areas including origination, servicing, general ledger, treasury and securitisation.

Phoebus has more than 25 clients across the UK and Ireland, with its technology supporting more than £120bn in assets.

Dale Langham, Information Security Officer at Phoebus Software, said, “This independent assessment provides our current and prospective clients with significant assurance that Phoebus continues to maintain robust controls aligned with recognised industry standards and best practice.”

He added, “Achieving another successful SOC 2 Type II attestation demonstrates the effectiveness of our control environment and further strengthens our ability to support client due diligence, supplier assurance, and information security requirements.”

Richard Pike, Chief Sales & Marketing Officer at Phoebus Software, said, “SOC 2 Type II attestation is increasingly recognised across the financial services sector as an important demonstration of effective security and control practices.”

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.