Published on June 02, 2026 (Updated on June 02, 2026)

SOC 2 Type II certification is how ChargeHub formally demonstrates what has always been true: that data security is built into how we operate, not bolted on. ChargeHub sits at the intersection of charging networks, mobility operators, and millions of EV drivers across North America, handling roaming sessions, payment transactions, user accounts, and business integrations every day. In 2026, we completed an independent third-party audit covering every system we run. This is what that means for our partners.

 

What Does SOC 2 Type II Actually Certify?

SOC 2 is an auditing framework developed for technology and data service companies. It evaluates whether an organization's controls around security, availability, and confidentiality actually work, not just whether they exist on paper.

The distinction between Type I and Type II matters. A Type I audit is a point-in-time assessment: it confirms that controls are designed correctly as of a specific date. Type II goes further. It examines whether those controls operated effectively over an extended period and is validated by an independent third-party auditor. That sustained, verified track record is what enterprise procurement and IT teams look for when evaluating a vendor.

For ChargeHub's partners, the certification isn't a self-assessment or a checklist. It's an external, time-tested validation of how we handle your data.

"SOC 2 Type II gave us a formal framework to validate what we were already doing. The audit process pushed us to document, test, and prove our controls over time, not just describe them."
Olivier Proulx, CTO, ChargeHub

Why Is Data Security Structural in Public EV Charging?

Public EV charging isn't a closed system. Every charging session connects multiple parties: the driver, the hardware, the charging network, the mobility operator, the payment processor. Data moves across all of them. In a roaming transaction alone, session credentials, authorization tokens, and billing records pass through several hands before a charge is confirmed.

ChargeHub sits at the center of that exchange. Passport Hub connects 27 roaming partners across the US and Canada, the most of any roaming solution in North America, and gives access to over 160,000 charging ports. We also operate one of the continent's leading public charging apps. That scale means the data flows we handle aren't incidental. They're critical infrastructure for the networks and operators that depend on them, making rigorous data governance a core operational requirement, not a compliance exercise.

"When you're the connective tissue between networks and operators, the security of your platform is everyone's problem. We took that responsibility seriously before SOC 2, and the certification formalizes that commitment."
— Olivier Proulx, CTO, ChargeHub

The EV charging industry is scaling fast. More networks, more operators, more drivers, more data. Maintaining trust at that scale requires controls that are independently verified rather than self-reported. That's exactly what SOC 2 Type II delivers.

What Does ChargeHub's SOC 2 Scope Cover?

ChargeHub's SOC 2 Type II audit covers every system we operate, with no carve-outs by product or data type. That includes the public-facing app used by EV drivers across North America, the business solutions and API integrations used by our charge point operator (CPO) and eMobility service provider (eMSP) partners, the roaming and payment data flowing through Passport Hub, and our internal operational infrastructure, including employee access and data handling.

That breadth is deliberate. A certification scoped to a single product line or a subset of data flows creates blind spots that partners must still assess independently. By submitting our full operations to the audit, we give partners a single, comprehensive point of reference for their due diligence.

Area Examples of what's covered
EV driver app User accounts, charging history, payment data
Business solutions Partner integrations, roaming data, API access
Internal systems Employee data, access controls, operational infrastructure

What Does This Mean for CPOs, eMSPs, and Mobility Operators?

The practical impact of SOC 2 Type II certification depends on who you are and how you work with ChargeHub.

CPOs and eMSPs integrating with ChargeHub's platform

  • Simplifies vendor due diligence for enterprise procurement and IT approval processes

  • Provides documented, third-party evidence of security controls, no custom assessment required

  • Audit report available on request under NDA

Mobility operators relying on Passport Hub for roaming

  • The infrastructure handling your session data and payment flows has been independently validated

  • Reduces the burden of ongoing partner security reviews

Prospects and new partners evaluating ChargeHub as an enterprise vendor

  • SOC 2 Type II signals operational maturity and a sustained investment in security

  • Formal documentation available to support your internal approval process

SOC 2 Type II: Certified Today, Re-Verified Every Year

Earning SOC 2 Type II certification doesn't close the file on security. The certification requires an independent audit every year. Controls are reviewed continuously. Any changes to our systems or processes are evaluated against the same standards that earned us the certification in the first place.

That annual cycle matters for partners. It means the report you receive today reflects current practices, not a one-time effort from a previous year. And it means ChargeHub's security posture evolves alongside the platform, not behind it.

"The annual audit cycle is what gives our certification its weight. Every year, we have to demonstrate that our controls still hold. That's not a burden: it's the point."
— Olivier Proulx, CTO, ChargeHub

FAQ

Is ChargeHub SOC 2 certified?

Yes. ChargeHub obtained SOC 2 Type II certification in 2026 following an independent third-party audit. The certification covers all ChargeHub products and services, including Passport Hub, the driver app, business solutions, and internal systems. It is renewed annually through a new audit cycle.

What is the difference between SOC 2 Type I and SOC 2 Type II?

SOC 2 Type I evaluates whether security controls are properly designed at a single point in time. SOC 2 Type II assesses whether those controls operated effectively over an extended period, verified by an independent third-party auditor. For partners evaluating ChargeHub as a vendor, Type II provides a stronger and more durable basis for trust than a point-in-time snapshot.

Does ChargeHub's SOC 2 certification cover roaming and payment data?

Yes. ChargeHub's SOC 2 Type II certification covers all products and services, including the data flows processed through Passport Hub: session credentials, authorization, and billing data involved in roaming transactions. The audit scope was not limited to a single product line or data category.

How does SOC 2 Type II compare to other security frameworks like ISO 27001?

SOC 2 Type II and ISO 27001 are complementary frameworks with different origins. ISO 27001 is an international standard focused on building and maintaining an information security management system. SOC 2 Type II is an auditing standard widely used in North America, focused on demonstrating that specific controls around security, availability, and confidentiality are operating effectively. For North American enterprise procurement processes, SOC 2 Type II is typically the primary reference.

How can I access ChargeHub's SOC 2 report?

ChargeHub's SOC 2 Type II audit report is available to partners and prospects on request, under a non-disclosure agreement. To request access, contact your ChargeHub account representative or reach out through our partner contact page