Continuous is independently audited and certified for SOC 1 Type 2 and SOC 2 Type 2. When your finance team closes the books, your audit trail needs to be airtight — and ours is.
As a platform that processes revenue-critical data between Salesforce and NetSuite, our controls need to meet the bar your finance and security teams require. Our certifications reflect a sustained operating period of audited controls — not a one-time snapshot.
Our certifications span both the financial reporting controls and security controls your teams need — across every platform we touch.
Security, availability, processing integrity, confidentiality, and privacy controls — verified over a sustained observation period. Covers all Continuous infrastructure that handles your data.
Financial reporting controls for systems that process your revenue data. Critical for companies with external audit requirements running Continuous alongside Salesforce ARM and NetSuite ARM.
Listed on the Salesforce AppExchange — security-reviewed and approved by Salesforce. Every AppExchange app must pass Salesforce's rigorous security review process.
View on AppExchange ↗Listed on the NetSuite SuiteApp Marketplace — reviewed and approved by Oracle NetSuite's partner program. Your NetSuite admin can install with confidence.
View on SuiteApp ↗Our Vanta-powered Trust Center includes real-time security posture, uptime history, subprocessor list, and access to our full compliance documentation. No NDA required to view most documents.
Open Trust Center ↗Most documentation is publicly accessible. Some detailed compliance reports may require an access code from your Continuous account team.
Our certifications aren't a checkbox. They reflect the nature of the data we touch and the teams who depend on it.
Usage events, billing records, and revenue schedules flow through Continuous. These determine what customers are invoiced and what gets recognized in your general ledger.
SOC 1 Type 2 directly addresses financial reporting controls. When your external auditors review your NetSuite ARM processes, Continuous needs to be in scope — and documented.
SOC 2 Type 2 demonstrates ongoing security and availability controls. We maintain this so your security team doesn't need to run a custom assessment from scratch every year.
For detailed audit reports, subprocessor lists, or compliance documentation beyond what's in the Trust Center, contact your account team or reach us directly.