Quick reference
Download the full document
Voight — SOC 2 Readiness Documentation
17 pages · Version 1.0 · June 2026Control-by-control mapping across CC1–CC9, Availability, and Confidentiality; the six known gaps; inherited vendor controls; and the documented path to a Type II report.
Readiness vs. certified — the difference
A readiness document that lists no gaps is not credible. Ours lists six — including the structural ones (segregation of duties in a founding-size team, no independent pentest yet) — together with the path to closing each.
What’s already in place
- Encryption everywhere — TLS 1.3 in transit, AES-256 at rest, API keys hashed
- No password storage — authentication delegated to Privy (SOC 2 Type II)
- Local-first privacy — 3-level PII scrubbing before telemetry leaves your process
- Incident response — written procedure with T+0 → T+7d timeframes
- Supply chain — Dependabot monitoring, npm provenance attestations, defined remediation SLAs
- Audited foundations — all three infrastructure vendors hold current SOC 2 Type II reports
The path to a Type II report
- Readiness (this document) ✓
- Gap closure (tracked in revisions)
- Compliance platform onboarding (continuous evidence)
- Optional Type I examination
- 3–12 month observation window
- Type II report — available to customers under NDA
See also
- GDPR — data protection alignment (covers the Privacy criterion)
- OWASP LLM Top 10 — LLM security alignment
- NIST AI RMF — AI risk management alignment
- Trust & Security — all our compliance frameworks