What Is SOC 2?
TL;DR
SOC 2 is a reporting framework from the AICPA under which a licensed CPA firm examines the controls a service organisation operates and issues an attestation report with an opinion. It is a report on controls rather than a certification or a pass mark, so the report itself is what a buyer should ask to read.
What does a SOC 2 report cover?
The examination is built on the AICPA Trust Services Criteria, of which there are five: security, availability, processing integrity, confidentiality and privacy. Security, the common criteria, is in scope for every SOC 2. The other four are included only if the organisation chose them, which is why two reports carrying the same name can cover very different ground.
That makes the scope statement the first thing to read and the description of the system the second. Both are written by the organisation being examined, and the auditor opinion addresses whether that description is fair and whether the controls meet the criteria. An opinion can be qualified, listing exceptions the auditor found, and those are the pages a serious vendor review reads first.
What is the difference between Type 1 and Type 2?
A Type 1 report addresses whether controls were suitably designed at a single point in time. A Type 2 report addresses design and operating effectiveness across a review period, commonly measured in months rather than days. Type 2 is what most vendor reviews ask for, because a control that existed on one date is a much weaker statement than one that demonstrably ran.
A report also covers a period that has already closed by the time anyone reads it. That is why buyers ask how recently the period ended and request a bridge letter covering the gap between that date and the review, rather than treating a report as a standing status.
Why is SOC 2 not a certification?
No certificate is issued and no body awards a pass. A CPA firm gives a professional opinion on a described system, and the language of certification does not apply to it, which is why the phrase SOC 2 certified is a category error and the phrase SOC 2 compliant is not a checkable claim. What is checkable is a specific report, for a stated scope, covering a stated period.
For that reason JaxSuite AI does not describe itself in certification language anywhere on this site. What is documented about mailbox access over OAuth, workspace isolation and data handling is on the security page, written to what can actually be shown, and a vendor review that needs paperwork should ask for it directly. This entry explains an accounting standard in plain language rather than offering audit or legal advice.
Frequently asked questions
No. It is a market expectation set by buyers rather than a statutory requirement, which is why it appears in procurement questionnaires and not in privacy legislation. GDPR Article 28(3) does require a processor to make information available to demonstrate compliance, and a report is one common way to do that, but the framework itself is voluntary.