We help other companies achieve SOC 2 attestation. We hold ourselves to the same standard.
soc2audit.ai is built and operated by Cyber Security Services — a CISSP-led cybersecurity firm founded in 2014 with a decade of experience delivering enterprise security programs, penetration tests, and SOC 2 engagements for Fortune 500 clients and high-growth startups.
We designed soc2audit.ai the way we’d want a compliance platform designed to hold our own customers’ data: encrypted end to end, hosted in a single geographic region, minimally privileged, continuously monitored, and reviewed against the same AICPA Trust Services Criteria our customers are audited against.
SOC 2 Type II — In Progress
AES-256 at rest · TLS 1.2+ in transit
US-only data residency
CISSP-led
soc2audit.ai runs on Microsoft Azure. Azure holds ISO 27001, SOC 1, SOC 2, SOC 3, FedRAMP High, HIPAA, and other certifications. See the Azure Trust Center for current attestations.
● Web application firewall protecting all public endpoints
● DDoS protection at the platform edge
● Private networking between application tiers
● No direct public access to databases or internal services
● Egress restrictions on production workloads
● Peer code review required for every production change
● Automated static application security testing (SAST) in CI
● Software composition analysis (SCA) to detect vulnerable dependencies
● Dependency updates on a defined cadence with expedited patching for critical CVEs
● Secrets managed in Azure Key Vault — never in source code
● Separate development, staging, and production environments
● Continuous vulnerability scanning of infrastructure and application
● Third-party penetration testing at least annually
● Documented remediation SLAs by severity
● Bug bounty program planned for Q4 2026
Production changes follow a documented change-management process including code review, automated testing, staged rollout, and rollback procedures.
All employees and contractors with access to production systems undergo background checks appropriate to their role and jurisdiction.
All employees sign confidentiality agreements as a condition of employment.
● Onboarding security training within 30 days of hire
● Annual security awareness refresh
● Role-specific training for engineers (secure coding) and support staff (data handling)
● Phishing simulation exercises
Employee devices accessing production systems are managed via mobile device management (MDM), full-disk encrypted, and monitored by endpoint detection and response (EDR).
Audit in progress with an independent AICPA-licensed CPA firm. Report available under NDA once issued.
Security, Availability, Processing Integrity, Confidentiality, and Privacy mapping maintained internally.
Standard Contractual Clauses in place for EU/UK data transfers. See Privacy Policy for details.
Full support for California resident privacy rights.
BAA available for customers in the healthcare sector on request.
If a framework you need isn't listed, ask us at security@soc2audit.ai — we may be able to accommodate under a specific engagement.
We use a small number of subprocessors to deliver the Service. Each subprocessor is vetted for security posture and contractually required to protect customer data. A current subprocessor list, including AI providers, is maintained at soc2audit.ai/subprocessors.
We provide 30 days’ notice of material subprocessor changes. Enterprise customers may opt in to subprocessor change notifications by email.
Please do not test against production customer data. Our public bug bounty program is planned for later in 2026.
Related questions or documentation requests (SOC 2 report, penetration test summary, security questionnaire), contact
For enterprise customers, request access to our full Trust Center at trust.soc2audit.ai (launching 2026).