Skip to main content
Archived document

SOC 2 Reports

Last updated

This document has been superseded.

The current version of this document is published at Security and Compliance. This page is preserved for reference and for any contract that explicitly cites it. The text below reflects the document as it was last updated above; subsequent changes are tracked only in the current version.

Read the current version: Security and Compliance

SOC 2 Reports

The System and Organization Controls (SOC) Reports are independent third-party examination reports that demonstrate how DuoCircle achieves its key compliance controls. The purpose of these reports is to help customers, prospects, and their auditors understand the controls established to support operations and compliance.

DuoCircle has been examined annually under SOC 2 Type 2 since 2022.

How to request the SOC 2 Type 2 report

DuoCircle’s SOC 2 reports are available to customers and serious prospects under a mutual non-disclosure agreement. We use the standardized Bonterms Mutual NDA, it’s published publicly so you can review it before you ask, no surprises.

The process:

  1. Review the NDA at the link above (publicly available, read it before you reach out).
  2. Contact us to request the SOC 2 report.
  3. Sign via the Bonterms web application using DuoCircle’s document signing software.
  4. Receive the report as soon as the NDA is executed.

No procurement gauntlet, no redline negotiations, no week-long back-and-forth. The standardized Bonterms NDA exists so that the only thing standing between a serious prospect and the SOC 2 report is a single signature on a contract you’ve already read.

What the SOC 2 Type 2 report covers

SOC 2 Type 2: Security, Availability, Confidentiality, Processing Integrity
What is the report?A description of DuoCircle’s controls environment plus an external audit of those controls against the AICPA Trust Services Criteria for Security, Availability, Confidentiality, and Processing Integrity
Under what standard?AICPA Examination Engagements; SOC 2 Type 2 (TSP section 100A, 2017 Trust Services Criteria)
Primary purposeIndependent assessment of the control environment for customers and users with a business need
AudienceUsers with a business need under NDA
CadenceAnnual, since 2022
AuditorHancock Askew & Co, LLP

Public trust signals (no NDA required)

While the full SOC 2 report requires an NDA (industry-standard practice), DuoCircle’s compliance posture is publicly verifiable through the Cloud Security Alliance:

The CSA STAR self-description, completed annually, summarizes DuoCircle’s compliance posture without disclosing the SOC 2 report itself. Use it for early-stage diligence.

Questions?

Contact us and we’ll get the SOC 2 report process started, typically a same-day response.


Questions about this document?

DuoCircle LLC, 5965 Village Way, Suite 105-234, San Diego, CA 92130. Email legal@duocircle.com for legal inquiries, or support@duocircle.com for everything else.