We ask our clients to trust us with access to their systems, strategies, and vulnerabilities. We believe that trust should be verifiable — not just promised.
Independently verified security controls — not a self-assessment.
A SOC 2 Type 2 audit is an independent examination by a licensed CPA firm under AICPA standards. Unlike a point-in-time assessment, a Type 2 report evaluates whether security controls are consistently followed over time. Our audit covered a full quarter and resulted in a clean opinion with no deviations noted.
Our audit covered two of the five AICPA trust service categories.
The system is protected against unauthorized access — both physical and logical. Includes access controls, network monitoring, change management, incident detection and response, and ongoing risk assessment.
Information designated as confidential is protected as committed. Includes data classification, access restrictions, secure disposal, and confidentiality commitments in all agreements.
Independently verified controls across six key areas.
Data encrypted in transit (TLS 1.2+) and at rest across all cloud platforms.
MFA required for all systems. No shared accounts. Least privilege access.
Security event logging, anomaly detection, and regular audit trail review.
Documented procedures, defined roles, communication protocols, and post-incident review.
Third-party risk assessment, SOC report review, and contractual security requirements.
Testing, approval, and rollback procedures for all system changes.
We use AI tools in our work — and we're transparent about it.
MTM uses AI to enhance our advisory services. All AI-assisted communications are disclosed. Client meeting recording requires explicit consent and can be revoked at any time. AI tools operate under enterprise licenses with data controls — client data is never used to train models.
Our full AI Tools Disclosure is available upon request or at mtm.now.
How we handle the information entrusted to us.
The complete SOC 2 Type 2 report is available to current and prospective clients, partners, and qualified parties under a non-disclosure agreement.
Request Report Or email info@mtm.now with the subject "SOC 2 Report Request"