What is SOC 2?
SOC 2 is an attestation framework defined by the AICPA (American Institute of Certified Public Accountants). A company asks an independent auditor to examine its controls against the Trust Services Criteria, and the auditor issues a report with its opinion.
It is a report, not a certification. The AICPA defines the criteria; it does not audit companies or approve individual reports. That is why Optidata says it has a SOC 2 Type II report, and never that it is SOC 2 certified.
What is the difference between Type I and Type II?
A Type I report describes how controls were designed at a single point in time. A Type II report tests whether those controls actually operated over an observation window.
Optidata's report is Type II: the auditor followed the controls for 90 days instead of checking them on one day.
What does Optidata's report cover?
Three of the five Trust Services Criteria are in scope: Security, Availability and Confidentiality. The auditor examined 88 controls, and the audit covers Optidata's cloud and its workplace platform.
The examination went past infrastructure and looked at how the company is run:
- Platform and infrastructure controls
- Internal processes and change management
- People management and access
- Financial controls
- Corporate governance
How long was the observation window?
90 days. The exact start and end dates of the period are stated in the report.
Who performed the audit?
An independent auditor. The auditor's name, its opinion and the dates of the period are in the report itself, which Optidata shares under NDA. Ask for the report to read them.
What does the report not cover?
Reading a SOC 2 report well means knowing its limits:
- It is not a certification, and it does not state that a system cannot be breached.
- It does not cover what you run on top of the platform: your access model, the operating systems you manage, your applications, data and keys.
- It covers Optidata's controls, not the data center facilities' own controls. The facilities have reports and credentials of their own, listed on the trust center.
- The Availability criterion examines controls. It is not an uptime commitment.
- It does not make Optidata PCI DSS compliant. PCI DSS compliance belongs to the data center facilities.
How do I request the report?
Three steps, and none of them is a procurement project:
Tell us what you need
Use the contact page or your account team and say which document you need: the SOC 2 report, ISO/IEC 27001 details, or answers to your own security questionnaire.
Sign the NDA
The report is confidential. An NDA is the only step between asking and reading it.
Review it before you sign
Your security and procurement teams get the report while they are still evaluating, not after the contract is closed.