Building

SOC 2 Type II

Third-party attestation covering security, availability, and confidentiality. The observation window is open. Auditor fieldwork and report issuance are targeted for Q4 2026. A readiness letter is available today on request.

Status Observation window active Report target Q4 2026 Trust categories Security, Availability, Confidentiality Last updated 2026-06-18
01  ·  What this means

What SOC 2 actually covers.

SOC 2 is an attestation from a licensed CPA firm confirming that specific controls were operational during the observation period. A Type II report covers a sustained window (typically 6-12 months) and provides stronger assurance than a Type I (point-in-time).

Praktend engaged an auditor in 2026. The observation window is running now. The report itself will be issued once fieldwork closes, which we expect in Q4 2026. Until then, we can provide a readiness letter describing the controls in scope and their current operating status.

We are not yet SOC 2 Type II certified. If your procurement floor requires a current, issued Type II report, we do not have one today and we will tell you that straight.

02  ·  Controls in scope

Controls the audit will cover.

These are the controls currently in the observation period. Status reflects current operational state, not auditor conclusions (those are not available until the report issues).

CC1 - Common Criteria

Role model enforces least-privilege. Two-axis identity separates app roles from per-company access.

Live
CC2 - Communication

Structured audit log on every agent action and approval. Append-only, carrying an idempotency key and reversal pointer per write.

Live
CC3 - Risk Assessment

Formal risk register and annual assessment process. Currently building documented process with assigned owners.

Building
CC4 - Monitoring

Centralized Cloud Logging on every Cloud Run service. Anomaly alerts on privileged actions in active build.

Live
CC5 - Control Activities

All production changes ship through CI with required code review. Pre-commit hooks block secrets and PII.

Live
CC6 - Logical Access

Required MFA on every operator account policy is building. Per-company data isolation is live at the Firestore rules layer.

Building
CC7 - System Operations

Automated daily backup to GCS. Cloud Run behind Firebase Hosting. No on-prem, no hand-rolled infrastructure.

Live
CC8 - Change Management

Branch-protected main. Feature branches require PR approval and passing CI before merge. Rollback runbooks in active build.

Live
CC9 - Risk Mitigation

Vendor register with contract-time security review is in active build. Annual third-party security assessments planned for 2027.

Building
A1 - Availability

Cloud Run scales to zero and up automatically. Static assets on Firebase Hosting CDN. Uptime monitoring active.

Live
C1 - Confidentiality

AES-256 at rest across Firestore, GCS, and Secret Manager. TLS 1.3 in transit on every public endpoint.

Live
P - Privacy

Customer-facing retention and deletion controls in build. PII scanner on every commit. Workspace BAA in force on every PHI flow.

Building
03  ·  The gap

What we cannot give you yet.

An issued SOC 2 Type II report

The report itself does not exist yet. The observation window is open and auditor fieldwork has not closed. We expect the report to issue in Q4 2026. If your procurement floor requires a current report today, we are not the right fit at this moment. We will say that directly rather than obscure it.

04  ·  Documents

What we can send you now.

Email chris@praktend.com with your request. Turn-around noted below.

Questions about our SOC 2 program?

Send your questionnaire or procurement requirements. Reply within twenty-four hours.

Send a question