Student First Technologies Achieves Second SOC 2 Type II Report

August 10th, 2026
Student First Technologies
At Student First Technologies (SFT), trust and security are foundational to our mission of transforming how K–12 education choice funding is managed and delivered. We're pleased to announce that SFT has received a SOC 2, Type II report for the period July 1, 2025 to April 30, 2026 and was issued by Aprio, LLP as of June 18, 2026.
This milestone reaffirms our ongoing commitment to operational excellence, data protection, and leadership in the evolving landscape of K–12 education choice programs.
Building on the SOC 2 Type II compliance we first achieved in June 2025, this second audited report confirms that our internal controls have not only remained in place but continued to operate effectively over an additional monitoring period as our platform and client base have grown.
What is SOC 2 Type II?
SOC 2 (System and Organization Controls 2) is a security and compliance framework developed by the American Institute of Certified Public Accountants (AICPA). It ensures that service providers securely manage data and adhere to best practices around privacy, availability, and confidentiality.
SOC 2 Type II is the gold standard in operational security audits; it validates not only the design of internal controls but also their real-world effectiveness over an extended monitoring period. A second audited report demonstrates that this effectiveness is sustained over time, not a one-time achievement.
Why It Matters
Maintaining SOC 2 Type II compliance is a clear signal of our long-term commitment to securing the financial and personal data entrusted to us by our clients and their users. For the public-sector programs we support, it also reinforces confidence that:
- Robust Safeguards Are in Place: We actively defend against unauthorized access, breaches, and fraud.
- Systems Are Stable and Dependable: Our infrastructure is monitored, hardened, and built for uptime and integrity.
- Compliance is Continuous: We operate with policies and procedures designed to meet the evolving expectations of regulators, auditors, and agency partners — and we validate them year over year.
The Path To A Second Audit Report
Like our first SOC 2, Type II report, this second audited report was the result of a methodical, company-wide effort. Our security and compliance team worked systematically to document, monitor, and test security controls across systems, operations, and policies throughout the audit window to meet the stringent requirements of the SOC 2 Type II framework.

We again engaged Aprio, a nationally recognized advisory firm specializing in SOC audits for high-growth SaaS and fintech companies, to conduct our independent audit. Their examination confirmed our continuous focus on our internal controls operating across the full audit period.
What's Next for Student First Technologies?
This second audited report reaffirms our role as a category leader in secure K–12 financial infrastructure, and we're just getting started. As education choice programs continue to grow nationwide, Student First will continue to help lead the way with innovative technology and programmatic services designed for accountability, transparency, and positive impact for families, schools, and education providers.
In particular, we are ramping up nationwide ahead of the 2027 federal tax credit scholarship program by partnering with scholarship granting organizations (SGOs). Our tax credit platform is tested and proven, and it operates under the same SOC 2 Type II standard that governs the rest of our infrastructure. This gives SGOs and their partners confidence that the systems managing tax credit scholarship funds meet rigorous, independently validated standards for security, availability, and confidentiality.
We are committed to setting the standard for public-sector fintechs serving education funding programs. Built to meet the expectations of state governments and nonprofit administrators while delivering a comprehensive experience for families and education providers, our end-to-end, white-label-ready modular platform, Theodore™, includes robust applications with integrated identity verification; high-volume direct and donation fund intake and management; digital wallets; integrated payments including the TheoPay™ smart debit card with real-time, item-level purchase adjudication; real-time reporting; and configurable program controls.
Requesting Our SOC 2 Type II Report
If you are a state agency, scholarship organization, or prospective partner and would like a copy of our SOC 2 Type II attestation, please contact us at compliance@studentfirsttech.com.
For more information about SOC compliance, please visit: www.aicpa.org/soc4so
About Student First Technologies
Based in Indiana, Student First Technologies is a bank sponsored fintech company that is implementing the infrastructure for education funding programs across the country in partnership with state agencies and non-profits.
For more information about Student First Technologies, you can connect with us here.
Website: www.studentfirsttech.com
Student First Technologies is a financial technology company, not an FDIC insured depository institution. Banking services provided by Bangor Savings Bank, Member FDIC. FDIC insurance coverage protects against the failure of an FDIC insured depository institution. Pass through FDIC insurance coverage is subject to certain conditions.
The Student First Technologies Mastercard® Debit Card is issued by Bangor Savings Bank, Member FDIC, pursuant to license by Mastercard International Incorporated. Mastercard is a registered trademark, and the circle design is a trademark of Mastercard International Incorporated. Spend anywhere Mastercard is accepted.
