Glossary · Privacy & data
SOC 2
Also said as
SOC 2 Type IISOC 2 Type 1service organization control 2
SOC 2 is an independent audit of a company's security practices — a passing report means a third party checked, not that your data is guaranteed safe.
Why it matters to your business
It's the fastest first filter on a vendor's trustworthiness: a real SOC 2 report is audited on a schedule and costs the vendor real money to maintain.
The catch · what vendors don't say
Type 1 is a one-time snapshot; Type 2 covers months of actual operation — and one vendor in our directory still hasn't publicly confirmed SOC 2 at all.