SOC 2

An audit standard from the AICPA evaluating a service organization's controls against the Trust Services Criteria: security, plus optional categories.

A SOC 2 report is produced by an independent auditor, not by the organization being audited, evaluating its controls against the AICPA's Trust Services Criteria. Security is required in every SOC 2 report; availability, processing integrity, confidentiality and privacy are each included at the discretion of the organization being audited, depending on which categories are relevant to what it does.

It is the audit security and procurement teams most commonly ask a software vendor to produce before approving a purchase, precisely because it comes from an independent third party against a defined, external standard, not a vendor's own description of its own controls.

A bank's vendor risk team requests a SOC 2 report as a condition of approving a new AI vendor, reviewed alongside its own security questionnaire before any contract is signed.

In Dynamiq, a SOC 2 audit is complete; the report is available under NDA on request, alongside HIPAA and GDPR documentation and details of the platform's credential storage, encryption and access controls.

Sources: AICPA & CIMA, SOC 2

See an agent on your own workflow.

Bring a process and its documents. Our engineers will show you how Dynamiq runs it, in your environment or ours.