SOC 2 compliance
Our plan to earn SOC 2, and how we can help you prepare for it.
Current status: in planning
Tylinks is not yet SOC 2 attested. This page describes what we intend to do. We will update it as each stage is completed.
What SOC 2 is
SOC 2 is an independent audit report, issued by a licensed CPA firm, on how a service organisation protects customer data. It is based on the AICPA Trust Services Criteria and is widely requested by enterprise customers, banks and investors during vendor due diligence.
Why we are pursuing it
- To give clients independent assurance about how we run monitoring, support and VPN services
- To meet vendor security requirements from regulated and international customers
- To hold ourselves to the same standard we help clients reach
Planned scope
| Trust criterion | Planned | What it covers |
|---|---|---|
| Security | Yes (required) | Protection against unauthorised access: access control, logging, monitoring, incident response |
| Availability | Yes | Uptime, backup, recovery and capacity for managed services and VPN |
| Confidentiality | Yes | Protection of client data and configuration |
| Processing integrity | To be decided | Accurate, complete and timely processing |
| Privacy | To be decided | Handling of personal information, aligned with the NDPA |
Our approach
- Scoping and readiness assessment. Define the systems and services in scope and identify gaps against the criteria.
- Policies and controls. Information security, access management, change management, vendor management, risk assessment, incident response and business continuity policies, with the controls to back them.
- Tooling and evidence. Continuous monitoring, logging and evidence collection so controls can be shown to operate.
- Type I report. An auditor confirms the controls are suitably designed at a point in time.
- Type II report. An auditor tests that the controls operated effectively over an observation period, typically three to twelve months.
SOC 2 readiness support for clients
If you are a fintech, software provider or service business that needs SOC 2 for customers or investors, we plan to offer readiness support alongside our existing compliance work.
- Scoping and gap assessment
- Policy and procedure preparation
- Technical control implementation and monitoring
- Evidence preparation ahead of your audit
Tylinks supports preparation. The SOC 2 report itself is issued only by an independent audit firm, and we cannot guarantee an audit outcome.
Interested in SOC 2 readiness?
Tell us where you are and what your customers are asking for.
Contact us