What is an SOC 2?
SOC 2 (System and Organization Controls 2) is an auditing framework, developed by the AICPA, that evaluates a service organization's controls against five Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy.
A SOC 2 report is produced by an independent CPA firm after examining an organization's actual controls, not just its policies. A Type I report attests that controls are suitably designed at a single point in time; a Type II report — the one most enterprise buyers actually require — attests that those controls operated effectively over a review period, typically three to twelve months, based on sampled evidence like access logs, change tickets, and incident records.
Security is the only mandatory criterion; the other four are selected based on what the organization actually promises customers. Because SOC 2 has no fixed checklist (unlike a certification with prescriptive requirements), the auditor evaluates whether the organization's own stated controls are reasonable and were actually followed — which is why continuous evidence collection (audit logs, access reviews, vendor due-diligence records) matters more than any one-time setup step.
In practice with Neotask
Neotask maintains its own SOC 2 control environment — encrypted-at-rest secrets, tenant-scoped access enforced from verified auth claims, append-only audit ledgers, and a documented evidence trail — so that when enterprise customers ask for a SOC 2 report as part of vendor security review, the underlying controls are already operating, not retrofitted for the audit.
Related terms
- iso-27001
- compliance-automation
- audit-log
- access-control
- data-encryption
Plans
Free
$0/mo
Download without a card and start for free.
Individual
$50/mo
The full personal agent platform for one person.
Business
$100/mo
One company workspace with room to add your team.
Enterprise
$200/mo
Multiple workspaces and capacity for larger teams.
Continue