← Security and Trust Centre
Framework 4 of 4

SOC 2 (Type I / Type II)

An AICPA attestation framework, not an ISO-style certification — independent assurance that our controls are designed, and then operated, effectively.

PLANNED / ROADMAPType I: month 3–5 · Type II: month 9–15
Type I vs Type II
Type I

Are the controls there? Proves controls are appropriately designed and implemented at a single point in time.

Type II

Did you consistently operate them? Proves controls operated effectively over an observation period, typically 6–12 months.

Trust Services Criteria we're scoping to
Security (Common Criteria)

Mandatory for every SOC 2 report — the foundation we are scoping to first.

REQUIRED
Availability

On the roadmap depending on final report scope.

OPTIONAL / ROADMAP
Confidentiality

On the roadmap depending on final report scope.

OPTIONAL / ROADMAP
Processing Integrity

On the roadmap depending on final report scope.

OPTIONAL / ROADMAP
Privacy

On the roadmap depending on final report scope.

OPTIONAL / ROADMAP
What we're building toward

SOC 2 draws on the same control set we're building for ISO 27001 — one control environment, not a separate audit trail:

Access controlChange managementMonitoringIncident responseVendor managementEncryptionBackup & recovery
Roadmap
Type I — Month 3–5

Targeted once ISO 27001 foundational controls are in place: proves controls are appropriately designed and implemented at a point in time.

Type II — Month 9–15

Observation period begins after Type I; proves controls operated effectively over a sustained 6–12 month window.

Request the SOC 2 roadmap & status

Get our current Trust Services Criteria scope and readiness timeline under NDA.

Request the pack →