What is SOC 2?
SOC 2 (System and Organization Controls 2) is an auditing framework developed by the AICPA that evaluates a service organization's controls related to security, availability, processing integrity, confidentiality, and privacy — the five Trust Service Criteria.
Our Current Status
🔄 SOC 2 Type II audit currently in progress.
Audit period: April 2026 — September 2026
Expected report: Q4 2026
Auditor: [Big 4 Accounting Firm]
Trust Service Criteria We Cover
⚙️
Processing Integrity
🔄
What We Do Today
- Encryption at rest: All data encrypted using AES-256 on AWS-managed storage
- Encryption in transit: TLS 1.3 for all API and web traffic
- Access control: Role-based access control (RBAC) with principle of least privilege
- Multi-factor authentication: Enforced for all internal systems and admin access
- Audit logging: Comprehensive logs retained for 12 months
- Vulnerability scanning: Weekly automated scans + annual penetration testing
- Incident response: Documented IR plan with 24-hour SLA for critical issues
- Background checks: All employees undergo background verification
Request Security Documentation
Enterprise customers may request our current security posture documentation, penetration test summaries, and compliance questionnaire responses at compliance@platemetrics.in