Rex achieves SOC 2 Type II
Rex is enterprise-grade by design, with isolated tenants, full audit logs and supervised agent autonomy, and is now officially SOC 2 Type II certified.

Rex agents work inside enterprise finance systems. We started SOC 2 within weeks of starting the company, before any customer asked us to.
When an agent can access an ERP, CRM, billing system and AR inbox, security is part of the product.
Rex runs order-to-cash operations for enterprise finance teams. Our agents work collections, portal submissions, disputes and cash application across thousands of customer accounts, which means they operate inside systems containing sensitive financial and customer data.
We designed the system around that from the beginning.
Each customer runs in an isolated tenant. Agent context and data do not cross between environments. Every action is logged with its reasoning, and new agent procedures begin supervised before graduating to higher levels of autonomy. Work that should always require human approval stays gated.
We use Anthropic models through AWS Bedrock, with inference running server-side inside Rex's infrastructure. Rex also supports SSO, role-based access controls, audit logs, encryption and EU data residency.
We started the SOC 2 process early because retrofitting security into an enterprise product later is much harder than building around it from the beginning.
On the engineering side, our infrastructure is defined as code, so the controls we rely on live alongside the infrastructure itself rather than in a separate manual process.
We worked with Oneleet through the SOC 2 process, including penetration testing and security tooling, and used Constellation as our independent auditor.
Rex is now SOC 2 Type II certified. The audit tested our controls over an observation period, and the report is available to customers on request.
You can learn more about our security posture at trust.rex.inc.