SOC 2 Type II
PrepSBA is committed to enterprise-grade security and compliance. Here's what SOC 2 means, where we are, and what we're building toward.
What is SOC 2 Type II?
SOC 2 (System and Organization Controls 2) is an auditing standard developed by the American Institute of Certified Public Accountants (AICPA). It evaluates service organizations on their controls related to five Trust Services Criteria (TSC):
Security
Protection against unauthorized access, both logical and physical.
Availability
Systems are available for operation and use as agreed upon.
Processing Integrity
System processing is complete, valid, accurate, and timely.
Confidentiality
Information designated as confidential is protected.
Privacy
Personal information is collected, used, retained, and disclosed appropriately.
Type I vs Type II: A SOC 2 Type I report evaluates whether controls are suitably designed at a point in time. Type II — the gold standard — evaluates whether those controls operated effectively over a defined period (typically 6–12 months). Type II provides significantly stronger assurance for enterprise customers.
Our Compliance Status
Controls Design & Documentation
Defining and documenting security controls across all five TSC domains. Policies, procedures, and evidence collection frameworks established.
Readiness Assessment
Internal readiness assessment with an independent advisor to identify gaps before formal audit. Remediation of findings.
Observation Period
Six-month evidence collection period with our appointed auditor. Controls are tested in operation during this window.
SOC 2 Type II Report
Issuance of the official SOC 2 Type II audit report by our CPA firm. Available to enterprise customers and lender partners on request.
Controls Already in Place
We don't wait for audit time to build good security. The following controls are active today:
- ✓AES-256 encryption at rest; TLS 1.3 in transit
- ✓Multi-factor authentication (MFA) for all accounts
- ✓Role-based access control (RBAC) with least-privilege principles
- ✓Comprehensive audit logging for all data access and administrative actions
- ✓Automated vulnerability scanning and dependency audits
- ✓Incident response plan and on-call security rotation
- ✓Data residency — all data stored in U.S.-based, SOC 2 certified cloud infrastructure
- ✓Annual penetration testing by independent third-party security firm
- ✓Vendor security reviews for all third-party integrations
Request Our SOC 2 Report
Once issued, our SOC 2 Type II report is available to enterprise customers and lender partners under NDA. Contact us to be notified when it's available.
Request Report — security@prepsba.com