What is SOC 2?
SOC 2 is an independent audit report on how a service provider handles data against five trust criteria - security, availability, processing integrity, confidentiality and privacy.
SOC 2 (Service Organization Control 2) is a reporting standard from the American Institute of CPAs. An external auditor examines a provider's controls against the relevant 'trust services criteria' and issues a report. It is not a pass/fail badge so much as a detailed, independent account of how the provider protects the data entrusted to it.
There are two flavours. A Type I report assesses whether the right controls are designed and in place at a single point in time. A Type II report is stronger: it tests whether those controls actually operated effectively over a period, usually six to twelve months. Type II is what enterprise buyers generally look for.
SOC 2 applies to an organisation, not to a piece of software you can buy. When a product says it is 'SOC 2 compliant', the meaningful question is who holds the report and what scope it covers - the product's own operator, or the infrastructure it is built on.
In 99 Data Rooms
How it works here.
99 Data Rooms runs on SOC 2 Type II certified infrastructure - its providers Supabase and Cloudflare hold those reports. 99 Data Rooms does not itself claim a SOC 2 report; the certifications belong to the underlying platforms. On top of that infrastructure, documents are UK-hosted in London, encrypted at rest, and gated per viewer, with a Data Processing Agreement available on request.
Common questions
SOC 2, in short.
Is 99 Data Rooms SOC 2 certified?
The SOC 2 Type II reports are held by its infrastructure providers, Supabase and Cloudflare. 99 Data Rooms builds on that certified infrastructure and does not claim to hold its own SOC 2 report. See the security page for the provider certifications.
What is the difference between SOC 2 Type I and Type II?
Type I checks that suitable controls are in place at a point in time. Type II tests that they operated effectively over a period, typically six to twelve months, which is why enterprise buyers usually ask for Type II.
Related terms
What is ISO 27001?
ISO 27001 is the international standard for information security management, certifying that an organisation runs a systematic, audited process for identifying and controlling security risks.
DefinitionWhat is UK data residency?
Data residency is the physical location where your data is stored and processed; UK data residency means it stays on servers within the United Kingdom rather than being moved abroad.
DefinitionWhat is a virtual data room?
A virtual data room (VDR) is a secure online space for sharing sensitive business documents with outside parties, where every viewer is controlled and every view is tracked.
Try it on a real document. Turn a PDF into a tracked, revocable link in a couple of minutes. Three rooms stay free for as long as you want them, no card required.