What is an SOC 2?

SOC 2 (System and Organization Controls 2) is an auditing framework, developed by the AICPA, that evaluates a service organization's controls against five Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy.

A SOC 2 report is produced by an independent CPA firm after examining an organization's actual controls, not just its policies. A Type I report attests that controls are suitably designed at a single point in time; a Type II report — the one most enterprise buyers actually require — attests that those controls operated effectively over a review period, typically three to twelve months, based on sampled evidence like access logs, change tickets, and incident records. Security is the only mandatory criterion; the other four are selected based on what the organization actually promises customers. Because SOC 2 has no fixed checklist (unlike a certification with prescriptive requirements), the auditor evaluates whether the organization's own stated controls are reasonable and were actually followed — which is why continuous evidence collection (audit logs, access reviews, vendor due-diligence records) matters more than any one-time setup step.

In practice with Neotask

Neotask maintains its own SOC 2 control environment — encrypted-at-rest secrets, tenant-scoped access enforced from verified auth claims, append-only audit ledgers, and a documented evidence trail — so that when enterprise customers ask for a SOC 2 report as part of vendor security review, the underlying controls are already operating, not retrofitted for the audit.

Related terms

Start free

Plans

Free

$0/mo

Download without a card and start for free.

Individual

$50/mo

The full personal agent platform for one person.

Enterprise

$200/mo

Multiple workspaces and capacity for larger teams.

Continue