Bybit has completed a SOC 2 Type II audit independently conducted by Deloitte, a milestone the exchange says reinforces its security governance, operational resilience and protection of sensitive information. The audit was reported on September 29, 2026, and covers controls that operated over a defined review period rather than a single point in time.
Developed by the American Institute of Certified Public Accountants, SOC 2 Type II is treated by financial institutions and global enterprises as a benchmark for security governance and operational resilience. Bybit, which describes itself as the New Financial Platform and says it is trusted by more than 80 million users worldwide, stated that the report adds independent assurance of its risk-management capabilities.
According to Bybit, the security framework combines governance, technology, processes and people, translating strategic security objectives into clear responsibilities. The audit tested whether those measures operated effectively throughout the review period. The company said user protection is a shared responsibility across the organization, not limited to security teams.
The exchange highlighted three areas supported by the report: reinforcing user trust, increasing transparency for institutional clients and partners, and upholding compliance standards. The report complements Bybit's existing ISO/IEC 27001 certification and PCI DSS compliance validation, which address different aspects of information security, data protection and payment-card security.
Bybit noted the report comes as institutional due diligence intensifies. A day earlier, FinanceFeeds reported that Franklin Templeton had extended an off-exchange tokenised collateral programme to Bybit, letting investors pledge money market fund shares worth roughly $686 million in net assets through ByCustody for USDT or USDC trading credit. Bybit said it will keep strengthening its security capabilities and use independent assessments to guide improvements.