Skip to content

Compliance & security

SOC 2 Type II

Independent audit of a vendor's security controls over a period of time.

SOC 2 Type II reports describe how a vendor's security controls *actually operated* over a sustained period (typically 6โ€“12 months), not just at a point in time (Type I). It's the strongest routine signal that a vendor has a real security program.

Ask for the report under NDA before purchase, and check the report *date* โ€” an old SOC 2 is a yellow flag.

See also

  • HIPAA โ€” US federal law protecting health information; the minimum compliance bar for US deployments.
  • ISO 27001 โ€” International standard for information-security management systems.