Certification In Progress

SOC 2 Type II Roadmap

We're pursuing SOC 2 Type II certification to provide independent assurance of our security and confidentiality controls.

Q3
Target: 2026
Type II
Audit Type
2
Trust Criteria
40%
Progress

What is SOC 2?

Understanding the certification we're pursuing.

SOC 2 (System and Organization Controls 2) is a widely recognized auditing standard developed by the American Institute of CPAs (AICPA). It evaluates how service organizations manage customer data based on five Trust Service Criteria.

A Type II report evaluates the design and operating effectiveness of controls over a period of time (typically 6-12 months), providing stronger assurance than a Type I report which only evaluates design at a point in time.

Trust Service Criteria

Security — In scope
Confidentiality — In scope
Availability — Future consideration
Processing Integrity — Future consideration
Privacy — Future consideration

Certification Timeline

Our journey to SOC 2 Type II certification.

Completed Q4 2025

Phase 1: Gap Assessment

  • ✓ Current state security assessment
  • ✓ SOC 2 criteria mapping
  • ✓ Gap identification
  • ✓ Remediation roadmap creation
In Progress Q1 2026

Phase 2: Control Implementation

  • ◐ Policy and procedure documentation
  • ◐ Technical control implementation
  • ○ Security awareness training
  • ○ Vendor risk management program

60% complete

Upcoming Q2 2026

Phase 3: Readiness Assessment

  • ○ Internal audit of controls
  • ○ Pre-audit readiness review
  • ○ Evidence collection system setup
  • ○ Auditor selection and engagement
Planned Q3 2026

Phase 4: Type II Audit

  • ○ Formal audit period begins (6 months)
  • ○ Control testing by auditors
  • ○ Evidence review and sampling
  • ○ Report issuance (target: Q3 2026)

Controls Being Implemented

Key security and confidentiality controls in our SOC 2 scope.

Security Controls

Access Control & Authentication Implemented
Network Security & Firewalls Implemented
Encryption (Transit & Rest) Implemented
Vulnerability Management In Progress
Security Monitoring & Logging In Progress
Incident Response Procedures Implemented

Confidentiality Controls

Data Classification Policy Implemented
Data Retention & Disposal Implemented
Confidentiality Agreements Implemented
Vendor Risk Assessment In Progress
Data Handling Procedures Implemented
Secure Data Destruction Planned

Organizational Controls

Information Security Policy Implemented
Risk Assessment Process Implemented
Security Awareness Training In Progress
Change Management Implemented
Business Continuity Plan In Progress
Board Oversight Implemented

What We Can Share Now

Available documentation while SOC 2 certification is in progress.

Transparency During Certification

While we work toward SOC 2 Type II certification, we're committed to being transparent about our security practices. We're happy to share available documentation with prospective and current customers upon request.

Available Now

  • Security whitepaper and architecture overview
  • Penetration test executive summary (annual)
  • Data Processing Agreement (DPA) template
  • Completed SIG Lite / CAIQ questionnaires
  • Subprocessor list with DPA status

Available After Certification

  • SOC 2 Type II Report (under NDA)
  • Bridge letter for report currency
  • SOC 3 Public Report (general use)

Frequently Asked Questions

Common questions about our SOC 2 certification.

Why Type II instead of Type I?

Type II provides stronger assurance by testing controls over a period of time (6-12 months) rather than just at a single point. While it takes longer to achieve, it's more valuable to customers evaluating our security posture.

Which Trust Service Criteria are in scope?

We're initially pursuing Security and Confidentiality criteria, which are most relevant for a SaaS application handling customer data. We may expand to include Availability in future audits.

Who will be the auditor?

We are currently in the process of selecting an AICPA-accredited CPA firm to conduct our audit. We expect to finalize engagement in Q2 2026. The auditor name will be disclosed in our SOC 2 report.

Can I see the SOC 2 report when it's ready?

Yes. SOC 2 Type II reports are shared under NDA with customers and prospective customers. We will also produce a SOC 3 report which is publicly available. Contact to request access once available.

What about ISO 27001?

ISO 27001 certification is on our roadmap for Q4 2026. Many of the controls we're implementing for SOC 2 also align with ISO 27001 requirements, which will accelerate that certification.

Stay Updated on Our Progress

Subscribe to receive updates when we achieve SOC 2 certification and other security milestones.

We'll only send SOC 2 and major security updates. No spam.