SOC 2 Type II
Independent validation of our security, availability, and confidentiality controls through a rigorous SOC 2 Type II audit.
What is SOC 2 Type II?
SOC 2 (Service Organization Control 2) is a framework developed by the American Institute of CPAs (AICPA) for managing customer data. A Type II report goes beyond design — it evaluates the operational effectiveness of controls over a period of time (minimum 6 months).
For quiXzoom, SOC 2 Type II demonstrates to enterprise customers that our systems and processes meet rigorous standards for protecting their data.
Trust Services Criteria
quiXzoom's SOC 2 audit covers the following criteria:
Security
The system is protected against unauthorized access, use, or modification.
In ScopeAvailability
The system is available for operation and use as committed or agreed.
In ScopeConfidentiality
Information designated as confidential is protected as committed or agreed.
In ScopeProcessing Integrity
System processing is complete, valid, accurate, timely, and authorized.
Planned — Phase 2Privacy
Personal information is collected, used, retained, and disposed of in accordance with commitments.
Planned — Phase 2Audit Timeline
Q2 2026
Readiness Assessment
Gap analysis and remediation of controls against SOC 2 requirements.
July 2026
Audit Period Begins
Independent auditor begins monitoring operational effectiveness of controls.
December 2026
Audit Period Ends
6-month observation period concludes. Auditor reviews evidence and tests controls.
Q1 2027
Report Issued
Final SOC 2 Type II report delivered. Available to enterprise customers under NDA.
Controls in Scope
The following control domains are evaluated during the SOC 2 audit:
- Access Control: Role-based access, MFA, least privilege, quarterly access reviews
- Change Management: Code review, CI/CD pipelines, deployment approvals, rollback procedures
- System Operations: Monitoring, alerting, incident response, backup and recovery testing
- Risk Management: Annual risk assessments, vendor due diligence, business continuity planning
- Data Security: Encryption at rest and in transit, key management, data classification
- Human Resources: Background checks, security training, confidentiality agreements
Request the Report
Enterprise customers and partners can request a copy of our SOC 2 Type II report under a standard NDA. Contact us at security@quixzoom.com with your organization details.