
ALLFINANZ Achieves Full SOC 2 Compliance Across All Five Trust Services Criteria
03/03/2026
properties.trackTitle
properties.trackSubtitle
ALLFINANZ, the advanced digital underwriting software solution of Munich Re Automation Solutions (MRAS), has successfully achieved full SOC 2 Type 2 compliance, marking an important milestone in its ongoing commitment to security, transparency, and operational excellence. This accomplishment reflects MRAS’ adherence to the highest standards of data protection and service reliability, validated through an extensive independent audit by the global leader in cybersecurity Prescient Security.
Fausto Teghillo, Chief Information Security Officer at MRAS, noted the SOC 2 Type 2 attestation report evaluates whether an organisation’s controls operate effectively over time.
What sets ALLFINANZ apart is its full compliance across all five SOC 2 Trust Services Criteria:
- Security
- Confidentiality
- Availability
- Privacy
- Processing Integrity
Insurance companies typically require their SaaS and InsurTech providers to meet the three criteria for Security, Confidentiality, and Availability. Achieving all five criteria is uncommon, making ALLFINANZ an outstanding category leader in the industry. This represents a higher standard of assurance for the insurers using ALLFINANZ.
The SOC 2 Type 2 report, issued by Prescient Security, affirms MRAS’ strong control environment and its dedication to safeguarding customer data. The audit also validated MRAS' system requirements, including encryption of customer data, adherence to SLAs, and a 99.9% platform uptime commitment.
The achievement not only strengthens customer trust but also reinforces its competitive position in highly regulated and data‑sensitive markets. With the SOC 2 journey now firmly embedded in its operational rhythm, ALLFINANZ SaaS by MRAS continues to evolve its compliance maturity - reducing manual audit effort and enhancing control monitoring - while maintaining transparency through its Customer Trust Centre.
The audit covered the period from January to November 2025 and required rigorous evidence collection and documentation to demonstrate compliance with the SOC 2 criteria. This was a continuous effort by the team and a true testament to our hard work. While we are very proud of this achievement, we continue to work every day to ensure ongoing compliance and improved security controls in the future.