There are two report types. A Type I report looks at one moment in time. It says the company's controls are well designed on that date. A Type II report goes further: the auditor watches the controls run over a period, often several months, and reports whether they worked the whole time. Buyers usually want Type II, because designing a control and actually running it are different things.
SOC 2 is not a certification, and there is no pass mark. It is not required by law either. It is a report, and it only covers the criteria the company chose to include. So when a vendor says they are SOC 2 examined, ask three things: which type, which criteria, and how recent the report is.
This matters for website tools because a chat widget sits on your site and holds contact details for the people who enquired. Clerkzo has been through a SOC 2 Type II examination, which is usually the piece of evidence a practice manager or IT reviewer asks for before approving a new tool.
Related terms
Browse all 104 terms- Personally Identifiable Information (PII)Personally identifiable information (PII) is any data that can identify a specific individual on its own or when combined with other information — names, email addresses, phone numbers, account identifiers and more.
- Data RetentionData retention is the policy and practice of deciding how long you keep each type of data before deleting it, based on how long you actually need it and what the law requires or permits.
- Data ResidencyData residency refers to the country or region where an organisation's data is physically stored, and to any requirement that it stay within a particular jurisdiction.
- Encryption at RestEncryption at rest means data is stored in an encrypted form, so that anyone who obtains the underlying storage — a disk, a backup, a database file — cannot read it without the decryption key.