United States (globally recognized)

SOC 2 Type II evidence captured continuously, not assembled before audit

SOC 2 — Service Organization Control 2

Access control records, availability monitoring, change management evidence, and incident documentation — generated continuously so SOC 2 auditors find a year of evidence ready.

CPA firms (AICPA-licensed auditors)United States (globally recognized)

30-day free trial · Private deployment included · Cancel anytime

About SOC 2

SOC 2 is an auditing framework developed by the AICPA that evaluates service organizations' controls related to security, availability, processing integrity, confidentiality, and privacy.

Top audit finding

"User access reviews not performed at required frequency with documented evidence"

Most common SOC 2 non-conformance finding

Requirement mapping

SOC 2 requirements — and how Certexi addresses them

Framework requirements

  • 1Security: access controls, encryption, and vulnerability management evidence
  • 2Availability: system monitoring, incident response, and recovery records
  • 3Change management: authorized changes with testing and approval records
  • 4Risk assessment: periodic evaluation with treatment records
  • 5Vendor management: third-party reviews and contractual commitments

Certexi approach

  • Access control records: provisioning, review, deprovisioning with timestamps and approvals
  • Incident management: detection, response, and post-incident review records
  • Change management workflow: request → approval → testing → implementation → verification
  • SOC 2 evidence portfolio: trust service criteria organized evidence with testing linkage

Industry relevance

Sectors where SOC 2 compliance applies

Core capabilities

Use cases central to SOC 2 compliance

PRECIOS

Alineado al Valor Operativo, No al Número de Usuarios

El precio depende del alcance del despliegue, no del número de usuarios. Tus datos. Tu infraestructura. Tus reglas.

Todos los planes incluyen despliegue privado. Tu información permanece en tu infraestructura.

ISO 27001 Aligned
Private Deployment
Unlimited Users

Piloto

Valida antes de comprometerte

Personalizado

5 lugares por trimestre

  • Despliegue completo de plataforma
  • Soporte de configuración
  • Capacitación e incorporación
  • Acceso directo al equipo de producto
  • Iteración basada en retroalimentación
  • Período de evaluación de 8 semanas

Estándar

Operaciones de una ubicación

Desde $2,500

por mes, facturado anualmente

  • Todas las capacidades centrales
  • Biblioteca de plantillas estándar
  • Despliegue privado incluido
  • Soporte por email (respuesta 24h)
  • Actualizaciones trimestrales
  • Usuarios ilimitados

Enterprise

Multi-ubicación, alto cumplimiento

Personalizado

Basado en alcance del despliegue

  • Todo lo de Estándar
  • Desarrollo de plantillas personalizadas
  • Ingeniero de soporte dedicado
  • Garantías SLA
  • Integraciones avanzadas
  • Opción de despliegue air-gapped

Despliegue Privado Incluido en Todos los Planes

Cada plan incluye despliegue completo en tu infraestructura — Nextcloud, servidores Linux, Docker, Kubernetes o entornos air-gapped. Tu información nunca sale de tu control.

SOC 2 evidence generated daily, not assembled under audit pressure.

30-day free trial. Private deployment on your infrastructure.

Start Free Trial