Skip to main content
ControlBirdControlBird
  • Features
  • Use Cases
  • Pricing
  • Docs
  • Blog
  • Log in Get Started
  • Dark Mode
Log in Get Started
← All standards
On roadmap

SOC 2

Service Organization Control 2 (Type II)

Overview

SOC 2 is an attestation framework from the AICPA, built around the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. A SOC 2 report is produced by an independent auditor and describes a service organisation’s controls. A Type II report goes further than a Type I by testing that those controls operated effectively across a period, typically several months to a year, rather than at a single point in time. Because the report attests to how a service is operated, it applies to a hosted service rather than to software you run yourself. ControlBird does not hold a SOC 2 report today; an attestation for the ControlBird cloud is on the roadmap. The product already provides the security, availability, and confidentiality controls such a programme builds on, and for self-hosted deployments those controls operate under your own audit scope. Contact sales for current posture.

Key requirements

Trust Services Criteria
Define controls against the relevant criteria — here security, availability, and confidentiality — covering how a service protects its systems and data and keeps them available.
Operating effectiveness over an audit period
A Type II report tests that controls did not merely exist on paper but operated effectively across a defined period, not only at a single moment.
Independent auditor attestation
The report is issued by an independent third-party auditor who examines the controls and their evidence, rather than being a self-declaration.
Documented controls and evidence
Maintain written policies and retain the operating evidence — access records, change history, monitoring output — that an auditor can sample to confirm each control ran as described.

How ControlBird aligns

Security and access control
Authentication through native accounts, LDAP and Active Directory, or OAuth 2.0, combined with role- and attribute-based permission rules enforced in the data layer down to the entity type, the field, and a branch of the tree. This gives the access-control evidence the security criterion expects.
Confidentiality
The Secret field type keeps sensitive values such as passwords and tokens protected at rest and redacted from logs and the interface, and TLS 1.2 and 1.3 protect data in transit across the web, the API, and the supported industrial protocols. Operator disk or volume encryption covers the remainder of data at rest.
Availability and recovery
Multi-node replication, leader election, and failover protect availability, and point-in-time snapshots with write-ahead-log replay support recovery — the availability criterion’s core concern.
Auditable change history
Every field write is attributed to the authenticated user and timestamped in the write-ahead log, and the historian can be configured to retain that change history for chosen entities and fields. This is the kind of operating evidence a Type II audit samples; forward service and protocol logs to your own monitoring stack or SIEM for retention and correlation.
What your organisation owns
SOC 2 is not a product certification: a Type II attestation covers how a service organisation operates, and ControlBird does not currently hold one. For self-hosted deployments the controls above run under your own audit scope; an attestation for the ControlBird cloud is on the roadmap. Contact sales for current posture rather than assuming a report exists.

Need this for a tender?

We can provide deployment-specific detail and supporting documentation for procurement and security reviews.

Talk to our teamBack to all standards
ControlBirdControlBird

Real-time automation platform for smart devices and industrial equipment.

Product

  • Pricing
  • Release Notes

Resources

  • Documentation
  • Walkthrough
  • Blog
  • Compare
  • Standards & Compliance
  • Status
  • GitHub

Company

  • Contact Sales
  • Support
  • Careers

Legal

  • Terms of Service
  • Privacy Policy

© 2026 Qureshi Enterprise Inc. All rights reserved.