Trust center · SOC 2

Optidata's SOC 2 Type II report: what it covers and how to request it

An independent auditor examined 88 Optidata controls for Security, Availability and Confidentiality over a 90-day observation window. The report is shared under NDA with customers and prospects.

The report in numbers

What the auditor looked at.

  • 88controls examined
  • 3trust services criteria in scope
  • 90 daysobservation window
  • 66pages in the report
  • 2025year Optidata received the report

What is SOC 2?

SOC 2 is an attestation framework defined by the AICPA (American Institute of Certified Public Accountants). A company asks an independent auditor to examine its controls against the Trust Services Criteria, and the auditor issues a report with its opinion.

It is a report, not a certification. The AICPA defines the criteria; it does not audit companies or approve individual reports. That is why Optidata says it has a SOC 2 Type II report, and never that it is SOC 2 certified.

What is the difference between Type I and Type II?

A Type I report describes how controls were designed at a single point in time. A Type II report tests whether those controls actually operated over an observation window.

Optidata's report is Type II: the auditor followed the controls for 90 days instead of checking them on one day.

What does Optidata's report cover?

Three of the five Trust Services Criteria are in scope: Security, Availability and Confidentiality. The auditor examined 88 controls, and the audit covers Optidata's cloud and its workplace platform.

The examination went past infrastructure and looked at how the company is run:

  • Platform and infrastructure controls
  • Internal processes and change management
  • People management and access
  • Financial controls
  • Corporate governance

How long was the observation window?

90 days. The exact start and end dates of the period are stated in the report.

Who performed the audit?

An independent auditor. The auditor's name, its opinion and the dates of the period are in the report itself, which Optidata shares under NDA. Ask for the report to read them.

What does the report not cover?

Reading a SOC 2 report well means knowing its limits:

  • It is not a certification, and it does not state that a system cannot be breached.
  • It does not cover what you run on top of the platform: your access model, the operating systems you manage, your applications, data and keys.
  • It covers Optidata's controls, not the data center facilities' own controls. The facilities have reports and credentials of their own, listed on the trust center.
  • The Availability criterion examines controls. It is not an uptime commitment.
  • It does not make Optidata PCI DSS compliant. PCI DSS compliance belongs to the data center facilities.

How do I request the report?

Three steps, and none of them is a procurement project:

  1. Tell us what you need

    Use the contact page or your account team and say which document you need: the SOC 2 report, ISO/IEC 27001 details, or answers to your own security questionnaire.

  2. Sign the NDA

    The report is confidential. An NDA is the only step between asking and reading it.

  3. Review it before you sign

    Your security and procurement teams get the report while they are still evaluating, not after the contract is closed.

SOC 2 FAQ

Short answers about the report.

Is Optidata SOC 2 certified?

Optidata has a SOC 2 Type II report. SOC 2 is an attestation, so the correct term is report, not certification: an independent auditor examined Optidata's controls for Security, Availability and Confidentiality over a 90-day observation window.

Can I get a copy of Optidata's SOC 2 report?

Yes, under NDA. Request it through the contact page and say you need the SOC 2 Type II report. Your security team gets it during evaluation, before you sign a contract.

Which trust services criteria are in scope?

Security, Availability and Confidentiality. Processing Integrity and Privacy are not in the scope of Optidata's report.

Does the SOC 2 report cover the data centers?

It covers Optidata's own controls. The data center facilities hold their own SOC 2 Type II report and other credentials, listed on the trust center.

Is the SOC 2 report public?

No. A SOC 2 report is written for customers, prospects and their auditors, so Optidata shares it under NDA instead of publishing it.

SOC 2 Type II

Read the report before you sign anything.

Ask through the contact page, sign the NDA, and your security team gets the full report during evaluation.