Skip to main content
Trust center

/

Roadmap · report target Q3 2027

SOC 2 Type II roadmap

Our SOC 2 Type II program is in progress. This page shows completed, current, and planned milestones; it does not claim certification or an available report.

Milestones

2026-Q1

Done

Architecture readiness

AWS multi-AZ + AES-256 at rest + TLS 1.2+ + Secrets Manager + IAM least-privilege. All foundational controls shipped.

2026-Q2

Done

GDPR-ready architecture

Privacy audit Wave 1-4 complete: data minimization, right to erasure flows, consent gates, biometric processing under Article 9(2)(a).

2026-Q3

In progress

Audit log + incident response baseline

Centralised audit trail (1-3 year retention per tier), incident response runbook, on-call rotation, breach notification protocol.

2026-Q3

Done

Auditor selection — Vanta + A-LIGN

Selected Vanta for compliance automation and A-LIGN as the independent audit firm for the SOC 2 Type II program.

2026-Q4

Planned

Readiness assessment

Vanta-driven gap analysis + A-LIGN human readiness review. Reviews policies, access controls, change management, vendor management, encryption — flags any remaining gaps for remediation before the 6-month observation window starts.

2027-Q1

Planned

Audit period kickoff

6-month observation window starts. Continuous evidence collection — control operating effectiveness over time, not just point-in-time.

2027-Q2

Planned

Audit period close

Auditor finishes evidence review. Exit interview + management response. Report drafting begins.

2027-Q3

Planned

SOC 2 Type II report issued

Final report available to customers under NDA. Annual re-audit cadence begins; report refreshed yearly with each Type II observation period.

Vendor selection

We use Vanta for compliance automation and A-LIGN as the selected audit firm.

Vanta — compliance automation platform

Vanta supports continuous evidence collection across our operating systems.

A-LIGN — audit firm

A-LIGN is the selected independent audit firm for the Type II engagement.

Why Type II, not Type I

SOC 2 Type I attests that controls existed at a point in time; Type II attests they operated effectively over a period (typically 6 months). Enterprise IT teams discount Type I — it's essentially a snapshot. Type II is the one they ask for.

We're skipping Type I and going straight to Type II to avoid the "useless milestone" trap. Adds about 6 months to the timeline but produces a report customers actually use.

Need to fill out a security questionnaire today?

Until the targeted Q3 2027 report is issued, we can provide:

CAIQ-Lite responses to the standard CSA Cloud Controls Matrix.

Custom responses to vendor-specific questionnaires (Vanta, Drata, SecurityScorecard imports — typically 3 business days).

Architecture diagrams + data flow descriptions, signed by engineering leadership.

Email security@svdy.com