SOC 2 Type II roadmap
Our SOC 2 Type II program is in progress. This page shows completed, current, and planned milestones; it does not claim certification or an available report.
Milestones
2026-Q1
Architecture readiness
AWS multi-AZ + AES-256 at rest + TLS 1.2+ + Secrets Manager + IAM least-privilege. All foundational controls shipped.
2026-Q2
GDPR-ready architecture
Privacy audit Wave 1-4 complete: data minimization, right to erasure flows, consent gates, biometric processing under Article 9(2)(a).
2026-Q3
Audit log + incident response baseline
Centralised audit trail (1-3 year retention per tier), incident response runbook, on-call rotation, breach notification protocol.
2026-Q3
Auditor selection — Vanta + A-LIGN
Selected Vanta for compliance automation and A-LIGN as the independent audit firm for the SOC 2 Type II program.
2026-Q4
Readiness assessment
Vanta-driven gap analysis + A-LIGN human readiness review. Reviews policies, access controls, change management, vendor management, encryption — flags any remaining gaps for remediation before the 6-month observation window starts.
2027-Q1
Audit period kickoff
6-month observation window starts. Continuous evidence collection — control operating effectiveness over time, not just point-in-time.
2027-Q2
Audit period close
Auditor finishes evidence review. Exit interview + management response. Report drafting begins.
2027-Q3
SOC 2 Type II report issued
Final report available to customers under NDA. Annual re-audit cadence begins; report refreshed yearly with each Type II observation period.
Vendor selection
We use Vanta for compliance automation and A-LIGN as the selected audit firm.
Vanta — compliance automation platform
Vanta supports continuous evidence collection across our operating systems.
A-LIGN — audit firm
A-LIGN is the selected independent audit firm for the Type II engagement.
Why Type II, not Type I
SOC 2 Type I attests that controls existed at a point in time; Type II attests they operated effectively over a period (typically 6 months). Enterprise IT teams discount Type I — it's essentially a snapshot. Type II is the one they ask for.
We're skipping Type I and going straight to Type II to avoid the "useless milestone" trap. Adds about 6 months to the timeline but produces a report customers actually use.
Need to fill out a security questionnaire today?
Until the targeted Q3 2027 report is issued, we can provide:
• CAIQ-Lite responses to the standard CSA Cloud Controls Matrix.
• Custom responses to vendor-specific questionnaires (Vanta, Drata, SecurityScorecard imports — typically 3 business days).
• Architecture diagrams + data flow descriptions, signed by engineering leadership.
