SOC 2 Reports
The System and Organization Controls (SOC) Reports are independent third-party examination reports that demonstrate how DuoCircle achieves its key compliance controls. The purpose of these reports is to help customers, prospects, and their auditors understand the controls established to support operations and compliance.
DuoCircle has been examined annually under SOC 2 Type 2 since 2022.
How to request the SOC 2 Type 2 report
DuoCircle’s SOC 2 reports are available to customers and serious prospects under a mutual non-disclosure agreement. We use the standardized Bonterms Mutual NDA, it’s published publicly so you can review it before you ask, no surprises.
The process:
- Review the NDA at the link above (publicly available, read it before you reach out).
- Contact us to request the SOC 2 report.
- Sign via the Bonterms web application using DuoCircle’s document signing software.
- Receive the report as soon as the NDA is executed.
No procurement gauntlet, no redline negotiations, no week-long back-and-forth. The standardized Bonterms NDA exists so that the only thing standing between a serious prospect and the SOC 2 report is a single signature on a contract you’ve already read.
What the SOC 2 Type 2 report covers
| SOC 2 Type 2: Security, Availability, Confidentiality, Processing Integrity | |
|---|---|
| What is the report? | A description of DuoCircle’s controls environment plus an external audit of those controls against the AICPA Trust Services Criteria for Security, Availability, Confidentiality, and Processing Integrity |
| Under what standard? | AICPA Examination Engagements; SOC 2 Type 2 (TSP section 100A, 2017 Trust Services Criteria) |
| Primary purpose | Independent assessment of the control environment for customers and users with a business need |
| Audience | Users with a business need under NDA |
| Cadence | Annual, since 2022 |
| Auditor | Hancock Askew & Co, LLP |
Public trust signals (no NDA required)
While the full SOC 2 report requires an NDA (industry-standard practice), DuoCircle’s compliance posture is publicly verifiable through the Cloud Security Alliance:
- CSA STAR Registry: cloudsecurityalliance.org/star/registry/duocircle/
- Level: Level 1 (CAIQ Lite, subset of CCM v4.1)
- Services listed: Alumni Forwarding, AutoSPF, DMARC Report, Outbound SMTP, Phishing Protection, Tenant Migration
The CSA STAR self-description, completed annually, summarizes DuoCircle’s compliance posture without disclosing the SOC 2 report itself. Use it for early-stage diligence.
Questions?
Contact us and we’ll get the SOC 2 report process started, typically a same-day response.
Questions about this document?
DuoCircle LLC, 5965 Village Way, Suite 105-234, San Diego, CA 92130. Email legal@duocircle.com for legal inquiries, or support@duocircle.com for everything else.