AssuranceLab
AssuranceLab is a Sydney-based cybersecurity audit firm specializing in SOC 2 Type I and Type II attestations for technology and SaaS companies. Founded in 2017, it was acquired by US accounting and advisory firm Sensiba in April 2025 to serve as its international cybersecurity audit arm.
- Company typePrivate
- Founded2017
- HeadquartersSydney, Australia
- Headcount11–50
- GTM typeB2B
- OfferingServices
What AssuranceLab does
AssuranceLab is a Sydney-headquartered cybersecurity audit and risk assurance firm founded in 2017 that specializes in conducting AICPA-aligned SOC 2 Type I and SOC 2 Type II certification audits for technology and SaaS companies. The firm acts as an independent third-party auditor, evaluating client control environments against the five Trust Services Principles — security, availability, processing integrity, confidentiality, and privacy — over a defined testing period, and issuing attestation opinions that customers, partners, and regulators rely on for trust validation. Its service delivery model is human-led, credentialed-auditor work, with no proprietary software platform disclosed in the source data; engagements are evidenced through published SOC 2 reports for clients such as Treno Scope, Voxel, and Felix.
On April 30, 2025, AssuranceLab was acquired by Sensiba, a US-based Certified B Corporation providing accounting, assurance, and advisory services. Post-acquisition, AssuranceLab operates as Sensiba's international cybersecurity audit arm within its Governance, Risk, and Compliance (GRC) practice, gaining cross-sell access to adjacent frameworks (ISO, HITRUST, CMMC, HIPAA, NIST, CDR attestations) and to Sensiba's broader industry verticals including venture capital, manufacturing, nonprofit, and agribusiness. Customer segmentation is horizontal, with the primary segment being technology and SaaS firms seeking SOC 2 certification as a sales-enablement and trust signal. Go-to-market is led by co-founder and co-CEO Paul Wenham in Australia, with North American coverage established through VP of Sales NAMER Ross Dolbec. Pricing is not publicly disclosed; revenue is generated per audit engagement on a services-fee basis.
AssuranceLab firmographics
Firmographics- Name
- AssuranceLab
- Legal name
- AssuranceLab
- Website
- https://assurancelab.com.au
- Company type
- Private
- Founded year
- 2017
- Operating status
- Acquired
- Headcount range
- 11–50 employees
- Short description
- AssuranceLab is a Sydney-based cybersecurity audit firm specializing in SOC 2 Type I and Type II attestations for technology and SaaS companies. Founded in 2017, it was acquired by US accounting and advisory firm Sensiba in April 2025 to serve as its international cybersecurity audit arm.
- Ownership category
- akta.pro rank
AssuranceLab industry classification
Industry- Product category
- Cybersecurity Compliance Auditing
- NAICS
- Security Systems Services (56162)
- akta.pro primary industry
- Audit & Assurance Services (BPAHABAA)
- akta.pro secondary industry
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC)
Keywords
Where AssuranceLab is headquartered
LocationHeadquarters
- HQ city
- Sydney
- HQ country
- Australia
- HQ region
- Oceania
Markets served
AssuranceLab business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales
AssuranceLab product offering
Product offeringCore offering
AssuranceLab conducts independent cybersecurity and compliance audits, with a primary focus on SOC 2 Type I and Type II certifications that assess client systems and processes against the AICPA's Trust Services Criteria covering security, availability, processing integrity, confidentiality, and privacy. Engagements are delivered to technology and SaaS organizations that need third-party validation of their security controls for customers, partners, and regulators.
Product overview
AssuranceLab is a cybersecurity audit and risk assurance firm headquartered in Australia. The company specializes in conducting security compliance audits, including SOC 2 Type I and Type II certifications, verifying that companies' systems and processes meet industry-standard trust service principles for security, availability, processing integrity, confidentiality, and privacy.
Differentiator
Problem solved
Functional benefit
Products and services
- SOC 2 Type II Audits Independent audit engagements that evaluate a client's security, availability, processing integrity, confidentiality, and privacy controls against the AICPA Trust Services Criteria over a sustained operating period. Delivered to technology and SaaS organizations that need long-term third-party validation of their control environment for enterprise customers and partners.
- SOC 2 Type I Audits Point-in-time SOC 2 certification audits that assess the design of an organization's security controls as of a specific date. Delivered to emerging technology platforms establishing initial compliance posture.
Companies that use AssuranceLab
Customer profileSegments2 records
Ideal customer profiles2 records
AssuranceLab technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AssuranceLab partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- SensibaflagshipSensiba, an accounting, assurance, and business advisory firm, acquired AssuranceLab on April 30, 2025. The acquisition was intended to expand Sensiba's international presence and enhance its cybersecurity and compliance services, incorporating AssuranceLab's expertise in cybersecurity audits and risk assurance into Sensiba's global operations.
Recent moves5 records
Expansion highlights4 records
AssuranceLab competitors and assessment
Company assessmentDirect peers
- Linford & Co. Specialty audit firm focused on SOC 2, ISO 27001, PCI, and HIPAA assessments for technology companies. Directly comparable specialist audit-only business model to AssuranceLab.
- BARR Advisory: Cybersecurity and compliance firm delivering SOC 2, ISO 27001, HITRUST, PCI, and FedRAMP audits to SaaS and technology clients. Closely comparable specialist audit positioning to AssuranceLab.
- Schellman & Co. U.S.-based specialty CPA firm focused on SOC 2, ISO 27001, PCI, HITRUST, and FedRAMP attestation audits. Most directly comparable to AssuranceLab in that it is an audit-first, non-Big-4 specialist competing in the same SOC 2 attestation market.
- A-LIGN: Cybersecurity and compliance audit firm providing SOC 2, ISO 27001, HITRUST, PCI DSS, and FedRAMP assessments, plus managed compliance services. Direct peer to AssuranceLab in cybersecurity attestation auditing, with a comparable technology-company client base.
- Coalfire: Large cybersecurity advisory and audit firm providing SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI assessments along with penetration testing. Comparable in core SOC 2 audit offering while operating at materially greater scale.
Broad incumbents
- Sensiba (parent): Acquirer and parent of AssuranceLab; Top-100 U.S. accounting and advisory firm with Audit, Tax, Consulting, GRC, and ESG practices. Comparable in that it now offers the same SOC 2 audit services AssuranceLab historically delivered, but as part of a much broader portfolio.
- KPMG Australia: Big Four firm offering assurance, advisory, and risk consulting including SOC 2 and ISO attestation in Australia. Overlaps with AssuranceLab's market but serves primarily large enterprises rather than mid-market SaaS.
Emerging players
- Drata: Compliance automation platform that streamlines SOC 2, ISO 27001, and HIPAA evidence collection for technology companies. Not a direct auditor but disrupts the SOC 2 market AssuranceLab serves by reducing manual audit effort.
- Vanta: Automated trust management platform that helps companies prepare for SOC 2, ISO 27001, HIPAA, and other audits. Comparable adjacent player whose automation tooling reshapes demand dynamics for traditional SOC 2 auditors like AssuranceLab.
Regional players
- PKF Australia: Mid-tier Australian accounting and assurance network with risk and compliance services. Regionally comparable to AssuranceLab in the Australian market, particularly for technology and growth-stage clients.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat3 records
Key risks5 records
Key highlights5 records
Customer concentration
AssuranceLab compliance and trust
Trust signalCompliance3 records
AssuranceLab financial estimates
Financial estimateRevenue estimate
Valuation estimate
AssuranceLab leadership team
Management profileNumber of profiles
Profiles2 records
AssuranceLab funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
AssuranceLab M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about AssuranceLab
What does AssuranceLab do?
AssuranceLab conducts independent cybersecurity and compliance audits, with a primary focus on SOC 2 Type I and Type II certifications that assess client systems and processes against the AICPA's Trust Services Criteria covering security, availability, processing integrity, confidentiality, and privacy. Engagements are delivered to technology and SaaS organizations that need third-party validation of their security controls for customers, partners, and regulators.
When was AssuranceLab founded?
AssuranceLab was founded in 2017. It employs 11 to 50 people.
Where is AssuranceLab based?
AssuranceLab is headquartered in Sydney, Australia, in the Oceania region.
Who are AssuranceLab's main competitors?
Direct peers on record are Linford & Co., BARR Advisory, Schellman & Co., A-LIGN and Coalfire. Broad incumbents are Sensiba (parent) and KPMG Australia. Emerging players are Drata and Vanta. PKF Australia is listed as a regional player.
Does AssuranceLab have an API?
No public API is recorded for AssuranceLab.
What industry is AssuranceLab in?
AssuranceLab's product category is Cybersecurity Compliance Auditing. Its primary akta.pro industry code is BPAHABAA, Audit & Assurance Services, with a secondary code of BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX). Its NAICS code is 56162.