← Back
SOC 2 Ready

SOC 2 Type II

PrepSBA is committed to enterprise-grade security and compliance. Here's what SOC 2 means, where we are, and what we're building toward.

What is SOC 2 Type II?

SOC 2 (System and Organization Controls 2) is an auditing standard developed by the American Institute of Certified Public Accountants (AICPA). It evaluates service organizations on their controls related to five Trust Services Criteria (TSC):

🛡️

Security

Protection against unauthorized access, both logical and physical.

⏱️

Availability

Systems are available for operation and use as agreed upon.

⚙️

Processing Integrity

System processing is complete, valid, accurate, and timely.

🔒

Confidentiality

Information designated as confidential is protected.

🙋

Privacy

Personal information is collected, used, retained, and disclosed appropriately.

Type I vs Type II: A SOC 2 Type I report evaluates whether controls are suitably designed at a point in time. Type II — the gold standard — evaluates whether those controls operated effectively over a defined period (typically 6–12 months). Type II provides significantly stronger assurance for enterprise customers.

Our Compliance Status

Phase 1
In Progress

Controls Design & Documentation

Defining and documenting security controls across all five TSC domains. Policies, procedures, and evidence collection frameworks established.

Phase 2
Q3 2026

Readiness Assessment

Internal readiness assessment with an independent advisor to identify gaps before formal audit. Remediation of findings.

Phase 3
Q3–Q4 2026

Observation Period

Six-month evidence collection period with our appointed auditor. Controls are tested in operation during this window.

Phase 4
Q4 2026

SOC 2 Type II Report

Issuance of the official SOC 2 Type II audit report by our CPA firm. Available to enterprise customers and lender partners on request.

Controls Already in Place

We don't wait for audit time to build good security. The following controls are active today:

  • AES-256 encryption at rest; TLS 1.3 in transit
  • Multi-factor authentication (MFA) for all accounts
  • Role-based access control (RBAC) with least-privilege principles
  • Comprehensive audit logging for all data access and administrative actions
  • Automated vulnerability scanning and dependency audits
  • Incident response plan and on-call security rotation
  • Data residency — all data stored in U.S.-based, SOC 2 certified cloud infrastructure
  • Annual penetration testing by independent third-party security firm
  • Vendor security reviews for all third-party integrations

Request Our SOC 2 Report

Once issued, our SOC 2 Type II report is available to enterprise customers and lender partners under NDA. Contact us to be notified when it's available.

Request Report — security@prepsba.com