SOC 2

AICPA Trust Services Criteria — Type I in progress, Type II planned.

All topics Type I — Q3 FY26
Overview

SOC 2 is the de-facto enterprise audit. Our control environment is mapped against the five Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy). We're in active engagement with our auditor for Type I certification this fiscal; Type II follows after a 6-month observation window.

Roadmap
Type I report
Targeted Q3 FY26 (Sep 2026). Audit firm: A.P. Sanzgiri & Co., Mumbai.
Type II report
Targeted Q1 FY27 (Apr 2027) after the 6-month observation window required by AICPA.
ISO 27001
Stage 1 audit complete (Mar 2026). Stage 2 + certification scheduled for Q4 FY26.
Controls already in production
Access management
SSO via OIDC, MFA enforced on every admin role, role-based access via the RBAC matrix in /settings/users.
Change management
All production changes via GitHub PR + 2-reviewer approval. CI runs lint + tests + DAST scan before merge.
Logging & monitoring
Structured logs to Azure Monitor with 90-day hot retention + 1-year cold. Metrics and alerts on every microservice.
Vendor risk
Sub-processor list maintained in /trust/sub-processors with annual review. SOC 2 reports requested from every vendor handling customer data.
Vulnerability management
Weekly scan of dependencies (Renovate + Snyk). External pentest annually; remediation SLA: critical 7 days, high 30 days.
Artifacts & references
Public docs link directly. Confidential artifacts available under NDA — request via enterprise sales.
Need more?
Want the unredacted dossier?
Auditors and procurement teams: we're happy to share our latest gap-assessment report under NDA. Hit "Request artifacts" below or email security@wareshare.in.