SOC 2
Ayrıca şöyle anılır SOC 2, System and Organization Controls 2, SOC 2 Type II, SOC 2 Type I
SOC 2 is an independent auditor's report on how well a company's internal controls actually protect the data it handles, not a pass/fail certificate like a driver's license, but an attestation, written by a licensed CPA firm, that specific controls the company claims to have were suitably designed and, for the more meaningful version, were actually operating effectively over a real period of time (commonly six to twelve months). It has become the default proof enterprise buyers in the US ask for before trusting a SaaS or infrastructure vendor with sensitive data.
The AICPA's framework defines two report types, and the difference matters: under it a Type I report checks whether controls were designed correctly at a single point in time, a snapshot, while a Type II report checks whether those same controls actually operated effectively across an observation period, which is a meaningfully stronger claim ("we said we do X" versus "an independent auditor watched us do X for six months and confirmed it happened"). When someone asks for "a SOC 2," they almost always mean Type II.
The report is scoped against the AICPA's Trust Services Criteria: five categories (security, availability, processing integrity, confidentiality, and privacy), of which security is mandatory and the other four are elected based on what the audited company actually does. A company processing biometric identity data, for instance, would typically scope in confidentiality and privacy alongside the mandatory security criterion.
Who actually built this
The American Institute of Certified Public Accountants (AICPA) defined the SOC framework and the underlying Trust Services Criteria. The actual audits are performed by independent, licensed CPA firms, never by the company under audit, and never by a vendor selling security software. Solidus has no role in this framework beyond, someday, being a company that could choose to be audited under it.
Solidus today
No Solidus product has undergone a SOC 2 audit of either type. No auditor has been engaged, no scope has been defined, and no report exists to point to. This sits on Solidus's 2027 roadmap, alongside the rest of the formal security-certification work, stated directly rather than left as an implied "in progress."
See also
ISO 27001 is the closest parallel: a different framework answering a similar "can I trust this vendor's security" question, with a management-system audit instead of a controls attestation. NIST iBeta is the narrower, biometric-specific certification a company running liveness/anti-spoof technology would separately need.
Nereden geliyor
Bunu başkası belirtti. Solidus bir araya getiriyor.
Defined and maintained by the AICPA (American Institute of Certified Public Accountants) as part of its System and Organization Controls (SOC) reporting framework, built on the AICPA's Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). Reports are produced by independent, licensed CPA firms, never by the company being audited and never by Solidus.
Bunu nasıl doğrularsınız
Solidus bunu inşa etmedi. Girdi kavramı açıklıyor.
None. There is no report to link to, because none has been produced.