United States (globally recognized)

SOC 2 Type II evidence captured continuously, not assembled before audit

SOC 2 β€” Service Organization Control 2

Access control records, availability monitoring, change management evidence, and incident documentation β€” generated continuously so SOC 2 auditors find a year of evidence ready.

CPA firms (AICPA-licensed auditors)United States (globally recognized)

Private deployment Β· Sovereign infrastructure Β· Architecture session included

About SOC 2

SOC 2 is an auditing framework developed by the AICPA that evaluates service organizations' controls related to security, availability, processing integrity, confidentiality, and privacy.

Top audit finding

"User access reviews not performed at required frequency with documented evidence"

Most common SOC 2 non-conformance finding

Requirement mapping

SOC 2 requirements β€” and how Certexi addresses them

Framework requirements

  • 1Security: access controls, encryption, and vulnerability management evidence
  • 2Availability: system monitoring, incident response, and recovery records
  • 3Change management: authorized changes with testing and approval records
  • 4Risk assessment: periodic evaluation with treatment records
  • 5Vendor management: third-party reviews and contractual commitments

Certexi approach

  • Access control records: provisioning, review, deprovisioning with timestamps and approvals
  • Incident management: detection, response, and post-incident review records
  • Change management workflow: request β†’ approval β†’ testing β†’ implementation β†’ verification
  • SOC 2 evidence portfolio: trust service criteria organized evidence with testing linkage

Industry relevance

Sectors where SOC 2 compliance applies

Core capabilities

Use cases central to SOC 2 compliance

PRICING

Aligned to Operational Value, Not User Count

Pricing scales with deployment scope, not headcount. Your data. Your infrastructure. Your rules.

All plans include private deployment. Your data never leaves your infrastructure.

ISO 27001 Aligned
Private Deployment
Unlimited Users
Currency

Pilot

Validate before you commit

Custom

5 spots per quarter

  • Full platform deployment
  • Configuration support
  • Onboarding and training
  • Direct product team access
  • Feedback-driven iteration
  • 8-week evaluation period

Standard

Single-location operations

From $4,800 / month

per month, billed annually

  • All core platform capabilities
  • Standard template library
  • Private deployment included
  • Email support (24h response)
  • Quarterly platform updates
  • Unlimited users

Enterprise

Multi-location, high-compliance

Custom

Based on deployment scope

  • Everything in Standard
  • Custom template development
  • Dedicated support engineer
  • SLA guarantees
  • Advanced integrations
  • Air-gapped deployment option

Private Deployment Included in All Plans

Every plan includes full deployment on your infrastructure β€” Nextcloud, Linux servers, Docker, Kubernetes, or air-gapped environments. Your data never leaves your control.

SOC 2 evidence generated daily, not assembled under audit pressure.

Private deployment on your infrastructure. Architecture session included.

Request Architecture Session