Gemini said on January 23, 2020, that it had completed an independent SOC 2 Type 2 examination covering its cryptocurrency exchange and Gemini Custody. Deloitte & Touche LLP conducted the examination, according to the company’s announcement and contemporaneous reporting by CoinDesk.

The development mattered because cryptocurrency venues were asking customers and institutions to entrust them with assets while the industry still lacked a uniform, public system for comparing operational safeguards. A recognized service-organization examination did not eliminate custody or exchange risk, but it gave qualified customers, auditors and oversight teams a more structured basis for evaluating Gemini’s controls.

Gemini characterized the result as a first for a cryptocurrency exchange and custodian. That superlative was the company’s claim, not a conclusion independently established by a comprehensive survey of every digital-asset service provider.

From control design to operating effectiveness

Gemini had announced a SOC 2 Type 1 examination in January 2019. The distinction was important: Gemini described the Type 1 work as an assessment of control design and implementation at a point in time, while the Type 2 examination evaluated whether the relevant controls operated effectively over a period.

SOC 2 is an assurance framework for controls at service organizations. The American Institute of Certified Public Accountants describes SOC 2 reports as addressing controls relevant to security, availability, processing integrity, confidentiality or privacy. Such reports are intended for users who need detailed assurance about the systems a service organization uses to process and protect information.

Gemini said the January 2020 examination covered both its exchange and custody product. That scope connected cybersecurity governance to two central functions of a crypto venue: operating a market interface and safeguarding customer assets. For institutional counterparties, evidence that controls had operated over time was more informative than a point-in-time description alone.

The announcement also placed Gemini’s security posture within the language used by established technology and financial-service vendors. That institutional signaling was significant in 2020, when crypto custodians were competing not only on supported assets and trading access but also on whether banks, funds and compliance teams could evaluate them through familiar assurance processes.

What the examination did not prove

A SOC 2 Type 2 examination should not be read as a guarantee that an exchange cannot be hacked, lose assets or suffer an operational failure. It concerns defined systems, controls, criteria and an examination period; it does not certify every business activity or remove market, liquidity, counterparty and legal risks.

Gemini’s January 23 announcement did not reproduce the Deloitte report, enumerate the tested controls or state the examination period. SOC 2 reports are commonly restricted-use documents rather than public audit files, so the surviving public record does not permit an independent control-by-control assessment. CoinDesk confirmed the announcement and Deloitte attribution but likewise did not publish the report.

Gemini also said it intended to complete a SOC 2 Type 2 examination annually. On January 23, 2020, that was a forward-looking commitment rather than a completed record of recurring examinations.

Later documentary context

Gemini’s current trust center subsequently listed the relevant SOC 2 Type 2 examination window as January 1 through September 30, 2019. That later-published listing helps identify the operating period but was not stated in the contemporaneous announcement and therefore should not be treated as information readers necessarily had on January 23, 2020.

Primary sourceGemini announcement: SOC 2 Type 2 examination

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.