Black Opal

SOC 2 Type 2

The leading assurance framework for technology service providers — and the standard the infrastructure behind our work is independently audited against.

AICPA

The Standard

What It Is

SOC 2 is the most widely recognised assurance framework for technology service providers — here's what it actually tests and why enterprise buyers rely on it.

Five criteria, not one baseline

SOC 2 is structured around five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. An organisation defines which criteria apply to their services — and a qualified auditor tests whether their controls genuinely satisfy them.

Type 2 means sustained evidence

A Type 2 report does not just assess whether controls exist at a single moment. It covers a defined audit period — typically six to twelve months — during which the auditor tests whether controls operated effectively and consistently. That sustained evidence is what makes it meaningful.

Governed by an accounting profession standard

SOC 2 reports are produced by licensed CPA firms under AICPA guidance. That gives them a level of professional accountability that self-assessments or vendor questionnaires simply cannot match.

Why It Matters

What It Means For You

Knowing your technology partner operates on SOC 2-audited infrastructure has real, practical consequences for your procurement and risk posture.

Standard requirement in technology procurement

Many enterprise and regulated-sector buyers require a current SOC 2 Type 2 report from technology service providers before signing a contract. It functions as independently verified assurance that a vendor's controls have been tested — not just described.

Confidence in how your data is handled

SOC 2's confidentiality and privacy criteria go beyond basic security. They address how data is classified, who has access, and what commitments a provider makes about use and retention — questions that matter to legal, compliance, and executive teams.

Accountability that holds under scrutiny

Because SOC 2 is produced by an independent auditor operating under professional standards, it carries a weight that internal security documentation cannot. When your own stakeholders or clients ask about your supplier's posture, a SOC 2 report is a credible answer.

How We Operate

SOC 2 in Practice

Our infrastructure runs on platforms that hold their own SOC 2 reports. Our internal practices are built around the same five criteria. Here is what that looks like day to day.

SOC 2-certified infrastructure, throughout

Every hosting environment we use holds its own SOC 2 report. Whether a system is deployed on public cloud or a dedicated hosting environment, we work exclusively with providers whose controls over security, availability, and confidentiality have been independently audited. That is a deliberate procurement requirement, not a coincidence.

Controlled access and audit trails

We apply the principle of least privilege across every engagement. Developers and engineers access only what the work requires, for only as long as it is needed. Access to production systems is logged and reviewed, and permissions are revoked on project completion.

Availability and resilience by design

The systems we build and manage are designed around the same availability principles SOC 2 tests for: defined recovery objectives, tested backup procedures, and infrastructure that degrades gracefully rather than failing completely.

Confidentiality and privacy in practice

Data we handle on behalf of clients is treated as confidential by default. Access is scoped, storage is governed, and we do not retain information beyond what the engagement requires. These are not policies written for an audit — they reflect how we work.

Related Services

Where This Shows Up

SOC 2's five criteria run through these parts of our practice in particular.

Work With Us

Controls That Hold

When you work with Black Opal, your systems and data run on infrastructure with independently audited SOC 2 controls — and are handled by a team that applies the same principles internally. If you'd like to understand how that applies to your specific requirements, we're happy to talk it through.