Security at soc2audit.ai

We help other companies achieve SOC 2 attestation. We hold ourselves to the same standard.

Security is a product feature, not a checkbox

soc2audit.ai is built and operated by Cyber Security Services — a CISSP-led cybersecurity firm founded in 2014 with a decade of experience delivering enterprise security programs, penetration tests, and SOC 2 engagements for Fortune 500 clients and high-growth startups.

We designed soc2audit.ai the way we’d want a compliance platform designed to hold our own customers’ data: encrypted end to end, hosted in a single geographic region, minimally privileged, continuously monitored, and reviewed against the same AICPA Trust Services Criteria our customers are audited against.

SOC 2 Type II — In Progress

Our own SOC 2 Type II audit is underway with an independent AICPA-licensed CPA firm. Report available under NDA on request.

AES-256 at rest · TLS 1.2+ in transit

All customer data encrypted at rest and in transit using industry-standard cryptography.

US-only data residency

Customer data is hosted exclusively in Microsoft Azure US regions. No data leaves the United States.

CISSP-led

Security program owned by a certified practitioner with a decade of enterprise-scale delivery experience.
Data Protection

How we protect your data

Encryption

Data isolation

Customer data is logically isolated in a multi-tenant architecture with row-level and application-level tenant scoping. Every data access is bound to an authenticated session and the requesting user’s tenant identifier.

Data residency

soc2audit.ai hosts all customer data in Microsoft Azure data centers located in the United States. We do not replicate customer data to non-US regions.

Backups and recovery

Data deletion

Upon account termination, customer content is deleted within 90 days. Backups purge on standard rotation. Certified deletion certificates available on request.
Access controls

Who can access what and how we know

Access to customer data

Customer access controls

Auditor access

When you designate an AICPA-licensed CPA firm as your auditor, we provide scoped, read-only access to your evidence and control status. Every auditor session is logged.
Infrastructure and application security

How the platform is built

Cloud hosting

soc2audit.ai runs on Microsoft Azure. Azure holds ISO 27001, SOC 1, SOC 2, SOC 3, FedRAMP High, HIPAA, and other certifications. See the Azure Trust Center for current attestations.

Network security

● Web application firewall protecting all public endpoints
● DDoS protection at the platform edge ● Private networking between application tiers
● No direct public access to databases or internal services
● Egress restrictions on production workloads

Secure development

● Peer code review required for every production change
● Automated static application security testing (SAST) in CI
● Software composition analysis (SCA) to detect vulnerable dependencies
● Dependency updates on a defined cadence with expedited patching for critical CVEs
● Secrets managed in Azure Key Vault — never in source code ● Separate development, staging, and production environments

Vulnerability management

● Continuous vulnerability scanning of infrastructure and application
● Third-party penetration testing at least annually
● Documented remediation SLAs by severity
● Bug bounty program planned for Q4 2026

Change management

Production changes follow a documented change-management process including code review, automated testing, staged rollout, and rollback procedures.

AI security

How we handle AI-processed data

soc2audit.ai uses large language models to power gap assessments, policy generation, user access reviews, vendor risk reviews, and evidence recommendations. Our AI security commitments:

Employee security

Background checks

All employees and contractors with access to production systems undergo background checks appropriate to their role and jurisdiction.

Confidentiality

All employees sign confidentiality agreements as a condition of employment.

Security training

● Onboarding security training within 30 days of hire
● Annual security awareness refresh
● Role-specific training for engineers (secure coding) and support staff (data handling)
● Phishing simulation exercises

Endpoint security

Employee devices accessing production systems are managed via mobile device management (MDM), full-disk encrypted, and monitored by endpoint detection and response (EDR).

Monitoring, logging, and incident response

Continuous monitoring

Incident response

Documented incident response plan covering identification, containment, eradication, recovery, and post-incident review. Tabletop exercises conducted at least annually.

Breach notification

If we determine a security incident has affected your data, we will notify you without undue delay and provide the information you need to meet your own regulatory notification obligations. Notification timelines follow applicable law (GDPR: 72 hours; state breach laws: as required).

Frameworks we operate against

SOC 2 Type II

Audit in progress with an independent AICPA-licensed CPA firm. Report available under NDA once issued.

AICPA Trust Services Criteria

Security, Availability, Processing Integrity, Confidentiality, and Privacy mapping maintained internally.

GDPR / UK GDPR

Standard Contractual Clauses in place for EU/UK data transfers. See Privacy Policy for details.

CCPA / CPRA

Full support for California resident privacy rights.

HIPAA

BAA available for customers in the healthcare sector on request.

If a framework you need isn't listed, ask us at security@soc2audit.ai — we may be able to accommodate under a specific engagement.

Business continuity

Availability commitments

Subprocessors and vendors

Third parties who process customer data

We use a small number of subprocessors to deliver the Service. Each subprocessor is vetted for security posture and contractually required to protect customer data. A current subprocessor list, including AI providers, is maintained at soc2audit.ai/subprocessors.

We provide 30 days’ notice of material subprocessor changes. Enterprise customers may opt in to subprocessor change notifications by email.

Reporting a security issue

Found a security issue?

We take vulnerability reports seriously and appreciate responsible disclosure.

Please do not test against production customer data. Our public bug bounty program is planned for later in 2026.

Contact

For security

Related questions or documentation requests (SOC 2 report, penetration test summary, security questionnaire), contact

For enterprise customers, request access to our full Trust Center at trust.soc2audit.ai (launching 2026).