SOC 2 Type II

Independent validation of our security, availability, and confidentiality controls through a rigorous SOC 2 Type II audit.

What is SOC 2 Type II?

SOC 2 (Service Organization Control 2) is a framework developed by the American Institute of CPAs (AICPA) for managing customer data. A Type II report goes beyond design — it evaluates the operational effectiveness of controls over a period of time (minimum 6 months).

For quiXzoom, SOC 2 Type II demonstrates to enterprise customers that our systems and processes meet rigorous standards for protecting their data.

Trust Services Criteria

quiXzoom's SOC 2 audit covers the following criteria:

Security

The system is protected against unauthorized access, use, or modification.

In Scope

Availability

The system is available for operation and use as committed or agreed.

In Scope

Confidentiality

Information designated as confidential is protected as committed or agreed.

In Scope

Processing Integrity

System processing is complete, valid, accurate, timely, and authorized.

Planned — Phase 2

Privacy

Personal information is collected, used, retained, and disposed of in accordance with commitments.

Planned — Phase 2

Audit Timeline

Q2 2026

Readiness Assessment

Gap analysis and remediation of controls against SOC 2 requirements.

July 2026

Audit Period Begins

Independent auditor begins monitoring operational effectiveness of controls.

December 2026

Audit Period Ends

6-month observation period concludes. Auditor reviews evidence and tests controls.

Q1 2027

Report Issued

Final SOC 2 Type II report delivered. Available to enterprise customers under NDA.

Controls in Scope

The following control domains are evaluated during the SOC 2 audit:

  • Access Control: Role-based access, MFA, least privilege, quarterly access reviews
  • Change Management: Code review, CI/CD pipelines, deployment approvals, rollback procedures
  • System Operations: Monitoring, alerting, incident response, backup and recovery testing
  • Risk Management: Annual risk assessments, vendor due diligence, business continuity planning
  • Data Security: Encryption at rest and in transit, key management, data classification
  • Human Resources: Background checks, security training, confidentiality agreements

Request the Report

Enterprise customers and partners can request a copy of our SOC 2 Type II report under a standard NDA. Contact us at security@quixzoom.com with your organization details.