Sample audit report — see how a Hackerbane report is structured. Open the report →

SOC 2 compliance

A SOC 2 report shows customers how you protect their data against the Trust Services Criteria. Hackerbane runs the readiness assessment, audits your controls for design and operating effectiveness, and prepares the evidence your CPA firm will test.

What SOC 2 is

SOC 2 is an attestation framework defined by the American Institute of CPAs. A licensed CPA firm examines your controls against the Trust Services Criteria and issues a report that your customers read under NDA. The criteria cover security, which is always in scope, plus availability, processing integrity, confidentiality, and privacy, which you include when your customers care about them.

A Type I report covers the design of your controls at a point in time. A Type II report covers whether those controls operated effectively over a period, and is what enterprise customers usually mean when they ask for SOC 2.

Who it applies to

  • SaaS and infrastructure providers selling to enterprise customers in North America and beyond.
  • Exchanges, custodians, and wallet-as-a-service platforms whose institutional clients run vendor due diligence.
  • AI product companies whose customers need assurance about how prompts, training data, and outputs are handled.
  • Any company answering the same security questionnaire for every deal and wanting one report to point to instead.

What Hackerbane does

  • Readiness assessment: we map your existing controls to the Trust Services Criteria you have chosen and tell you which points of focus have no control, a weak control, or no evidence.
  • Control design: we help you define controls that fit how your engineering team actually works, so the examination tests reality rather than a policy nobody follows.
  • Controls audit: we test each control for design and, for Type II, for operating effectiveness across a sample period, the same way your CPA firm will.
  • Technical testing: penetration testing and code review that satisfy the vulnerability management and change management criteria, including for smart contract deployments and AI pipelines where those are part of the service.
  • Evidence collection: we set up the evidence your examiner will request so it is produced by the system rather than assembled by hand at the end.
  • Remediation and examination support: control exceptions are fixed and retested, and we answer the examiner's technical questions with you.

What you get

  • A readiness report against every criterion in scope, with priorities and owners.
  • A tested control matrix mapped to the Trust Services Criteria.
  • Technical findings with severity, proof for the serious ones, and a fix for each.
  • An evidence pack organised the way a CPA examiner requests it, and verified remediation before the examination period closes.

Who signs off

A SOC 2 report is issued by a licensed CPA firm after its own examination. Hackerbane prepares you for that examination and fixes the controls that would produce exceptions; the opinion in the report is the CPA firm's.

Questions

Should we start with Type I or Type II?
Most companies get a Type I first to prove the controls are designed correctly, then run the observation period for a Type II. If customers are already asking for Type II and your controls have been operating for a while, we can prepare you to go straight to it. The readiness assessment tells you which is realistic.
Does Hackerbane issue the SOC 2 report?
No. Only a licensed CPA firm can issue a SOC 2 report. We do the readiness, controls audit, technical testing, and remediation that come before the examination, and we work alongside the CPA firm you choose.
Which criteria should we include beyond Security?
Include the criteria your customers ask about in their questionnaires. Availability is common for infrastructure and custody platforms, confidentiality for anyone handling client data, and privacy where personal data is processed. Adding criteria adds controls and evidence, so we scope them during readiness.

Next step

Request an audit

Tell us whether you need a Type I or Type II report, which Trust Services Criteria your customers ask about, and when the examination period is meant to start. We will propose a readiness assessment and controls audit with an estimate.