Field Notes · Blog · 26 Aug 2026

Navix Is Now SOC 2 Type II Attested

Navix has completed a SOC 2 Type II examination. Here's what an independent auditor verified, why it matters for freight audit and payment data, and how security teams can review the full report.

A freight audit vendor asking for your invoice data is asking for a map of your business. Carrier rates. Lane volumes. Payment terms. Dispute history. The margins you’ve negotiated and the ones you haven’t. Hand that to the wrong platform and the exposure is your negotiating position, sitting in someone else’s database.

Which is why the first serious question in any freight audit evaluation isn’t about features. It’s “prove this data is protected.”

Navix can now answer that question with an auditor’s signature. Navix has completed a SOC 2 Type II examination, conducted by an independent CPA firm against the Security criteria of the AICPA Trust Services Criteria.

What Type II means, and why the distinction matters

There are two kinds of SOC 2 report, and the difference is the whole point.

A Type I report is a snapshot. An auditor reviews the controls on a single day and confirms they’re designed properly. It answers “do the right policies exist?” — a question any vendor with a good compliance consultant can pass.

A Type II report tests operation. The auditor observes an extended period and verifies that the controls actually ran, consistently, the entire time. How access to systems was granted and revoked as people joined and left. How every change to the platform was reviewed before it shipped. How incidents were detected and handled. How third-party vendors were assessed before they touched anything.

Policies on paper versus controls in production. Enterprise security teams ask for Type II because it’s the version that can’t be staged for the audit.

What this changes for shippers, brokers, and 3PLs

Navix sits in the middle of the invoice-to-payment flow. Carrier invoices come in, line-item audits run, disputes resolve, payments go out. Every step touches data a customer would never post publicly.

Before an attestation, a vendor evaluation handles that risk with a security questionnaire: 200 rows in a spreadsheet, three weeks of back-and-forth, answers written by the vendor about itself. The questionnaire cycle exists because buyers had no better instrument. Now there is one:

The Navix Trust Center holds the full SOC 2 Type II report and supporting security documentation. Request access with a work email; reports are shared under NDA, and most requests turn around quickly. A security team mid-assessment can read the auditor’s own testing results instead of waiting on questionnaire rounds.

The Navix status page publishes uptime and incident history in real time. No login, no request form. If something’s degraded, the status page says so before an email does.

The security overview covers what the examination tested and where to route vendor-assessment questions.

Four questions to ask any freight audit vendor

Evaluating platforms in this category? These four separate marketing from evidence, whatever vendor is across the table:

  1. Type I or Type II? A Type I answer to a Type II question is a tell. Snapshot compliance is a weekend project; sustained operation is not.
  2. Can our security team read the actual report? “We’re SOC 2 compliant” on a website is a claim. A report your team can review under NDA is proof.
  3. Is system status public? A vendor that publishes its incident history is betting its reputation on its reliability. A vendor that doesn’t is asking you to.
  4. Who answers security questions, and how fast? The response path matters when there’s a real incident. If routing a question takes a sales rep and a week, that’s the incident response preview.

Navix’s answers: Type II, yes under NDA at the Trust Center, yes at status.navix.io, and [email protected] or your account team.

The audit period is over, but the controls it tested aren’t seasonal — the same access reviews, change controls, and monitoring run today. That’s the practical meaning of Type II: evidence the system works the way the documentation says it does.

Security teams mid-evaluation can skip the questionnaire cycle: request the report at trust.navix.io.

See it on your own data.

Bring your tariffs, your TMS, and 30 days of invoices. We'll show you a fully autonomous audit running on your live data.