Quick reference
| Field | Value |
|---|---|
| Framework | AICPA Trust Services Criteria (2017, rev. 2022) |
| Criteria in scope | Security (Common Criteria) · Availability · Confidentiality |
| Out of scope | Processing Integrity · Privacy (covered by GDPR, a stricter regime) |
| Certification status | Not certified — readiness phase, Type II on roadmap |
| Inherited attestations | Vercel, Railway, Privy — all SOC 2 Type II |
| Known gaps | 6, published in §6 of the document |
| Security Contact | team@voight.xyz |
| Document Version | 1.0 — June 2026 |
Download the full document
Voight — SOC 2 Readiness Documentation
17 pages · Version 1.0 · June 2026Control-by-control mapping across CC1–CC9, Availability, and Confidentiality; the six known gaps; inherited vendor controls; and the documented path to a Type II report.
Readiness vs. certified — the difference
| Readiness (this) | SOC 2 Type II | |
|---|---|---|
| Produced by | Voight (self-assessment) | Licensed CPA firm |
| Attests | Controls designed & documented | Controls operated effectively over 3–12 months |
| Independent verification | None | Yes |
What’s already in place
- Encryption everywhere — TLS 1.3 in transit, AES-256 at rest, API keys hashed
- No password storage — authentication delegated to Privy (SOC 2 Type II)
- Local-first privacy — 3-level PII scrubbing before telemetry leaves your process
- Incident response — written procedure with T+0 → T+7d timeframes
- Supply chain — Dependabot monitoring, npm provenance attestations, defined remediation SLAs
- Audited foundations — all three infrastructure vendors hold current SOC 2 Type II reports
The path to a Type II report
- Readiness (this document) ✓
- Gap closure (tracked in revisions)
- Compliance platform onboarding (continuous evidence)
- Optional Type I examination
- 3–12 month observation window
- Type II report — available to customers under NDA
See also
- GDPR — data protection alignment (covers the Privacy criterion)
- OWASP LLM Top 10 — LLM security alignment
- NIST AI RMF — AI risk management alignment
- Trust & Security — all our compliance frameworks