[Blog](/blog-category/blog/) October 2, 2024

# Scarf Completes SOC 2 Type 2 Examination: What It Means for Our Community

We're thrilled to announce that Scarf has successfully completed the SOC 2 Type 2 examination! This might sound like legal jargon at first glance, but let’s break down what this means for us, our users, and the open-source community as a whole.

By Scarf

![Scarf Completes SOC 2 Type 2 Examination: What It Means for Our Community](/imported/social-og/aa4f3662a49baf9a-af68161e.png)

We’re thrilled to announce that Scarf has successfully completed the SOC 2 Type 2 examination! This might sound like legal jargon at first glance, but let’s break down what this means for us, our users, and the open-source community as a whole.

## **So, What Is SOC 2 Type 2?**

In short, SOC 2 is a widely respected standard that companies (especially those handling sensitive data) use to prove they have robust controls in place to keep data safe and secure. It’s all about trust.

There are two types of SOC 2 reports, and we’ve just completed the Type 2 examination. Type 2 doesn’t just check if we have the right policies and procedures in place; it examines whether we’ve consistently followed them over time. This type of evaluation takes months of review to make sure that we’ve got our act together when it comes to security, availability, and confidentiality.

For companies and organizations that rely on Scarf, this examination is a solid proof that we’re committed to handling data responsibly and securely.

## **Why It Matters to Scarf**

At Scarf, our mission is to empower open-source maintainers and companies with deeper insights into how their software is being used. Open source has always been about transparency, collaboration, and trust. When we talk about giving maintainers and companies the tools to better understand how their projects are used, it’s critical that the data we manage is safe.

Completing the SOC 2 Type 2 examination is a big step in showing that we’re serious about protecting the integrity of the data that’s shared through Scarf Gateway, Scarf SDK, and Scarf Insights. It’s about ensuring that when users and organizations trust us with their data, they know that trust is well-placed.

## **Why It Matters to You**

If you’re a developer, company, or organization that uses Scarf, completing the SOC 2 Type 2 examination means peace of mind. You can feel confident that your data is being handled with top-tier security standards. Whether you’re tracking usage stats or leveraging Scarf’s insights to grow your project, you can rest easy knowing that your information is secure.

It’s also a reminder of Scarf’s commitment to continually improving. SOC 2 isn’t just a box we’ve checked—it’s an ongoing process. We’ll continue to evaluate and enhance our security practices to meet and exceed the trust our community places in us.

## **Moving Forward**

This milestone is just one piece of the larger puzzle. As we continue to build and grow, we remain committed to fostering trust and transparency in the open-source ecosystem. Completing the SOC 2 Type 2 examination is an important achievement, but it’s just one part of our journey. We’ll keep raising the bar for what it means to work with and support open-source software.

Thank you for being a part of the Scarf community. We look forward to continuing to serve you with the security and transparency you deserve.

[Get a Demo](/contact)

Related Resources

[![](/imported/posts/open-source-ai-index-og.png)

Blog Aug 11, 2026

### Ollama Ahead of Azure? A New Leaderboard for Open Source AI Adoption

What Scarf's package data tells us about a fast-moving market.



](/post/a-new-index-for-tracking-open-source-ai/)[![](/imported/posts/company-unlocks-value-og.png)

Blog Jun 8, 2026

### Getting the Most Out of Your Company Unlock Credits

Company unlocks are most useful when you filter, size, sort, and schedule them around the organizations you actually care about.



](/post/how-to-maximize-the-value-of-your-company-unlocks/)[![](/imported/posts/maven-central-publishers-scarf-thumbnail.png)

Blog Jun 4, 2026

### What 3,600+ Maven Central publishers do after claiming their namespace on Scarf

Scarf has now onboarded 3,693 open source organizations from Maven Central as part of our partnership with Sonatype. We now have a meaningful signal on how these teams are leveraging Scarf most effectively.



](/post/what-3600-maven-central-publishers-do-after-claiming-their-namespace-on-scarf/)

Article Notes [**Browse all resources**

Search, categories, and latest Scarf writing.

](/resources)[**See pricing**

Understand how Scarf packages its offering.

](/pricing)

On this page [So, What Is SOC 2 Type 2?](#so-what-is-soc-2-type-2)[Why It Matters to Scarf](#why-it-matters-to-scarf)[Why It Matters to You](#why-it-matters-to-you)[Moving Forward](#moving-forward)
