What is SOC 2 & Why is it important?
SOC 2 or Service Organization Controls 2 is a framework that is governed by the American Institute of Certified Public Accountants (AICPA). With a SOC 2 audit, an independent service auditor will review an organization’s policies, procedures, and evidence to determine if their controls are designed and operating effectively. A SOC 2 report communicates a company’s commitment to data security and protection of customer information.
Improving your security posture
SOC 2 compliance exemplifies an organization’s commitment to their customer’s trust and is a major milestone towards improving their overall security posture. With increasing cybersecurity threats and data breaches, it is paramount that organizations prioritize information security and the protection of their systems and data. By undergoing a SOC 2 audit, our controls and processes were validated by a third-party who attests to the functioning of the controls relevant to our application.
Why we pursued SOC 2 now
SOC 2 compliance is an integral step in proving to customers, stakeholders, and interested parties that our organization values their trust and has effectively implemented security controls. At our company’s stage, we realized that it was an ideal time to pursue this as it is important to protect data and mitigate potential security risks early and on an ongoing basis.
We have served a wide range of companies over our lifetime. This is another step in our dedication to trust, and a foundation that will enable us to build with new partners and customers for years to come. In a time when security is being rethought as AI-driven capabilities advance the market, we believe a commitment to safe practice and security controls is necessary regardless of company size, goal, or industry.
Compliance Partners
- Vanta: We partnered with Vanta, the leader in the Trust Management space, to help us automate the collection of our audit evidence. Vanta provides us with the strongest security foundation to protect our customer data.
- Advantage Partners: Our audit firm, Advantage Partners, was extremely helpful in creating a seamless audit experience. With their guidance and support, we were able to achieve SOC 2 compliance in a swift, efficient manner.
Lessons Learned
- Start early. It's easy to implement a new process, but harder to change a process already in place. We're grateful to have developed our systems with good security practice in place, enabling us to react quickly and effectively to anything that may come our way.
- Assign owners. Security is a company-wide process, but completing a review like this in a timely manner requires key stakeholders to be accountable to deadlines and changes.
- The right partners are key. Ironically, during our SOC 2 process, a large vendor had a publicity incident which questioned the reliability and trustworthiness of the process. SOC 2 itself has its own set of criticisms, but it does not reduce the importance of strong security practices and accountability for both your company internally, and your external customers. We are grateful to our partners for a smooth and engaging co
What's Next
SOC 2 compliance is a strong checkpoint and something we are proud to have achieved.
We will bring our dedication to trust, transparency, and due diligence to our partners and to the ecossytem as we continue to build towards a safer digital future.



