Glossary
SOC 2
An independent audit report describing how a vendor handles security and availability, produced by an outside firm and commonly requested before a tool is approved.
In plain terms
An outside firm examined how a vendor runs its security and wrote a report about it. The report is not a pass mark and not a certificate; it is a description of what the vendor said it does, what the auditor tested, and what the auditor found. That makes it far more informative than a badge and considerably more effort to use.
Why it matters
Because it is usually the most substantial evidence a buyer can get about a vendor's practices, and because it is routinely treated as a box rather than a document. A team that collects the report and files it has obtained a fact about whether one exists. A team that reads the scope and the exceptions has obtained something about how the vendor actually operates, which is what the exercise was for.
How it works
There are two types and the difference is decisive. One describes how things were arranged at a single point in time; the other describes whether the arrangements actually operated over a period of months. The second is the substantive one, because a control that exists on paper and a control that ran reliably all year are different claims, and only one of them has been tested.
The report defines its own scope, and the scope is where a report can be technically accurate and practically unhelpful. It covers named systems and services, and a vendor with several products may hold a report covering some of them. Checking that the scope includes the thing you are buying is a two-minute step that is skipped more often than any other.
The exceptions section is the part worth reading and the part nobody reads. It records what the auditor found that did not work as described, and a report with a few honestly recorded exceptions and clear responses is generally more reassuring than one with none. What matters is whether the vendor noticed, explained and addressed them.
It is periodic rather than continuous, so it describes a window that has already closed. A report always covers the past, sometimes a while in the past, and nothing in it speaks to what happened since. Asking when the current one ends and what the vendor's cadence is tells you more about the future than re-reading the last one does.
It is not a certification and there is no register to look up. An audit firm produces a report for the vendor, who chooses whom to share it with, usually under a confidentiality agreement. That is why the artefact arrives through a sales conversation rather than being published, and why a claim on a web page is not the same as the document.
Two ways to use the same report
Seen in the wild
Asking for the report covering an assistant's administered tier before a team's use of it becomes something people depend on.
ChatGPTChecking that a search tool's report covers the connectors reaching into internal systems, not only the core product.
GleanReading what an automation platform's report says about access to the credentials it stores for other services.
Make
Common misconceptions
People assume
Having one means the vendor is secure.
In fact
It means an outside firm examined described practices within a defined scope over a defined window, and wrote down what it found. That is genuinely valuable and it is a description rather than a verdict, which is why the scope and the exceptions carry the information and the existence of the report carries very little.
People assume
A report with no exceptions is the best outcome.
In fact
Not necessarily. A few honestly recorded exceptions with clear responses often indicate an auditor who looked and a vendor who engaged. What matters is whether anything found was understood and addressed, which is a judgement a reader makes rather than a score the document carries.
People assume
It covers the whole company.
In fact
It covers what its scope says it covers, which may be some products and not others, or a core service without the integrations around it. A vendor can hold a genuine report that does not include the specific thing you are about to buy, and nothing is wrong with either party when that happens.
Telling them apart
SOC 2 vs ISO 27001
SOC 2
A report describing what was examined and found. Read it.
A certification that a management system meets a standard. Verify it.
One produces a document with detail in it; the other produces a status. Buyers often accept either.
Questions
- What should we actually look at?
- Three things: which type it is, what the scope covers, and what the exceptions section records. Those carry nearly all the information in the document, and the existence of a report carries almost none. The scope check in particular takes two minutes and is the one most often skipped.
- What is the difference between the two types?
- One describes how arrangements stood at a point in time; the other describes whether they operated over a period. The second tested something the first did not, which is why it is the substantive one and why it is worth asking which you have been handed.
- Why can we not just look it up?
- Because it is a report to the vendor rather than an entry on a register, and it is usually shared under confidentiality. That is why it arrives through a sales conversation, and why a compliance claim on a web page is a different thing from the document itself.
- How current does it need to be?
- Every report covers a window that has closed, so what matters is when the current one ends and whether the vendor produces them on a regular cadence. Asking those two questions tells you more about what happens next than a careful reading of an old report does.
Key takeaways
- It is a description of what was examined and found, not a pass mark.
- The type tells you whether controls were tested over time or only described.
- Check that the scope covers the product you are actually buying.
- The exceptions section carries the information; a clean report is not automatically better.
- It always describes a window that has already closed.
Last checked July 2026