
Thrive Completes SOC 2 Type 2 Examination Again: What It Means for Your Plant's Data
Lean Technologies has completed its SOC 2 Type 2 examination for the Thrive platform for the third consecutive year. The audit was performed by independent audit firm Sensiba LLP and covered the period of August 1, 2025, through July 31, 2026.
For the manufacturers who run their maintenance, quality, safety, and continuous improvement programs on Thrive, this is more than a badge on a website. It's an independent check that the systems protecting their data work the way they're supposed to.
What Is SOC 2?
SOC 2 is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA). An independent CPA firm examines how a software provider protects customer data, measured against a set of standards called the Trust Services Criteria.
SOC 2 isn't a certificate you earn once and hang on the wall. It's an attestation: an independent auditor's formal opinion based on evidence gathered and tested during the audit. It has to be renewed every year to stay current.
Type 1 vs. Type 2: Why the Difference Matters
There are two kinds of SOC 2 reports, and the difference is significant.
A Type 1 report looks at whether a company's security controls are designed properly at a single point in time. It answers the question "Do the right policies and procedures exist?"
A Type 2 report goes further. Auditors test whether those controls actually operated effectively over a period of months. It answers a harder question: "Did the company follow its own rules, consistently, day after day?"
Thrive's report is a Type 2, the more rigorous of the two.
Why This Matters on the Shop Floor
Plants that move off paper and spreadsheets gain a lot: real-time visibility, faster response to downtime, and cleaner audit trails. They also put more of their operational data into software. That data includes work orders, inspection records, safety incidents, and production performance.
That's why IT and security teams at manufacturing companies are asking harder questions about software vendors than they used to. Before approving a new platform, they want to know:
Where the data is hosted and how it's backed up
Who can access it, and how that access is controlled
Whether an independent third party has verified the vendor's security claims
A current SOC 2 Type 2 report answers that last question directly. It also gives IT teams documented evidence instead of a sales promise, which often shortens vendor security reviews considerably.
"Our customers trust us with the data that runs their shop floors, and that trust has to be earned again every year," said Kale Sparling, Vice President at Lean Technologies. "Completing our SOC 2 Type 2 examination again shows our customers' IT and security teams that the controls behind Thrive aren't just written down. They're tested, and they work."
How SOC 2 Fits Into Thrive's Security Program
The SOC 2 Type 2 report is one part of a broader security and compliance approach:
Microsoft Azure hosting, fully managed by Lean Technologies, with automatic security patching and redundant backups across availability zones
Independent annual penetration testing to find and fix vulnerabilities
GDPR compliance for data privacy
Single Sign-On (SSO) through OpenID Connect, so users log in with identity providers like Azure AD and Okta
Role-based access controls that let operations teams manage who sees and edits what
Because Thrive is browser-based and hosted by Lean Technologies, there's no infrastructure for your IT team to maintain and no desktop software to install or patch.
What's Next
Security isn't a one-time project. Lean Technologies will continue its annual SOC 2 examinations and penetration testing, and will keep building security into the platform as Thrive adds new capabilities.
Request the Report
Current and prospective customers can request a copy of Thrive's SOC 2 Type 2 report under a non-disclosure agreement. Contact your Lean Technologies representative or visit the trust.leantech.com site.
Evaluating shop floor software and want to see how Thrive handles maintenance, quality, safety, and CI on one platform? Book a 15-minute screen share to see it in action.




