The leading assurance framework for technology service providers — and the standard the infrastructure behind our work is independently audited against.
AICPA
The Standard
SOC 2 is the most widely recognised assurance framework for technology service providers — here's what it actually tests and why enterprise buyers rely on it.
SOC 2 is structured around five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. An organisation defines which criteria apply to their services — and a qualified auditor tests whether their controls genuinely satisfy them.
A Type 2 report does not just assess whether controls exist at a single moment. It covers a defined audit period — typically six to twelve months — during which the auditor tests whether controls operated effectively and consistently. That sustained evidence is what makes it meaningful.
SOC 2 reports are produced by licensed CPA firms under AICPA guidance. That gives them a level of professional accountability that self-assessments or vendor questionnaires simply cannot match.
Why It Matters
Knowing your technology partner operates on SOC 2-audited infrastructure has real, practical consequences for your procurement and risk posture.
Many enterprise and regulated-sector buyers require a current SOC 2 Type 2 report from technology service providers before signing a contract. It functions as independently verified assurance that a vendor's controls have been tested — not just described.
SOC 2's confidentiality and privacy criteria go beyond basic security. They address how data is classified, who has access, and what commitments a provider makes about use and retention — questions that matter to legal, compliance, and executive teams.
Because SOC 2 is produced by an independent auditor operating under professional standards, it carries a weight that internal security documentation cannot. When your own stakeholders or clients ask about your supplier's posture, a SOC 2 report is a credible answer.
How We Operate
Our infrastructure runs on platforms that hold their own SOC 2 reports. Our internal practices are built around the same five criteria. Here is what that looks like day to day.
Every hosting environment we use holds its own SOC 2 report. Whether a system is deployed on public cloud or a dedicated hosting environment, we work exclusively with providers whose controls over security, availability, and confidentiality have been independently audited. That is a deliberate procurement requirement, not a coincidence.
We apply the principle of least privilege across every engagement. Developers and engineers access only what the work requires, for only as long as it is needed. Access to production systems is logged and reviewed, and permissions are revoked on project completion.
The systems we build and manage are designed around the same availability principles SOC 2 tests for: defined recovery objectives, tested backup procedures, and infrastructure that degrades gracefully rather than failing completely.
Data we handle on behalf of clients is treated as confidential by default. Access is scoped, storage is governed, and we do not retain information beyond what the engagement requires. These are not policies written for an audit — they reflect how we work.
Related Services
SOC 2's five criteria run through these parts of our practice in particular.
The SOC 2-compliant hosting environments we design, deploy, and manage — built on infrastructure with independently audited controls.
Software built with security, availability, and processing integrity as first-class requirements — not afterthoughts.
Data pipelines and analytics platforms where confidentiality and privacy controls are embedded from the ground up.
Automated systems and AI integrations designed with the same access controls and data governance principles SOC 2 requires.
Work With Us
When you work with Black Opal, your systems and data run on infrastructure with independently audited SOC 2 controls — and are handled by a team that applies the same principles internally. If you'd like to understand how that applies to your specific requirements, we're happy to talk it through.