Blog

BlueTally is SOC 2 Type II Certified

April 19, 2024

As our customers trust BlueTally with important data, security has always been a top priority for our team. As part of that commitment, we're proud to share that our IT asset management software is now SOC 2 Type II certified, verified through independent annual audits.

This post explains what SOC 2 actually covers, the difference between Type I and Type II, and what our certification means for your data in practice.

What SOC 2 Compliance Means

SOC stands for System and Organization Controls, a framework established by the American Institute of Certified Public Accountants (AICPA). Within SOC 2, the AICPA defines five Trust Services Criteria that a service organization can be assessed against: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is the foundation every SOC 2 report must include, and organizations add further criteria based on the commitments they make to customers.

Compliance isn't a questionnaire. An organization must implement controls that meet the chosen criteria, operate them consistently, and then have an independent CPA firm evaluate two things: whether the controls are suitably designed, and whether they actually operate effectively in day-to-day practice.

Type I vs. Type II: Why the Difference Matters

A Type I report is a snapshot. The auditor examines your controls at a single point in time and confirms they are well-designed and in place on that day.

A Type II report is the harder test. The auditor observes your controls operating over an extended audit period, a minimum of several months, and verifies they worked the entire time. Take a control like "all changes to production must be reviewed before deployment": in a Type II audit, the CPA firm samples changes made throughout the whole period and confirms each one was actually reviewed as stated. Passing once is design; passing continuously is discipline.

That's why Type II is the report security teams ask for during vendor reviews, and it's the one we hold.

Our SOC 2 Journey

We achieved our SOC 2 Type I attestation in December 2023 and have now completed our Type II audit. We maintain certification through annual Type II audits, each covering a full audit period rather than a point in time.

Two partners make this sustainable as an ongoing practice rather than a yearly scramble: we use Vanta to continuously monitor our controls, so drift gets caught in days instead of at audit time, and Prescient Assurance, an independent CPA firm, performs the comprehensive audit each cycle.

What This Means for Your Data

In practical terms, SOC 2 Type II certification means the security measures you'd hope for are independently verified to be operating, all the time: encryption in transit and at rest, enforced two-factor authentication, role-based access controls, reviewed changes to production, monitored infrastructure, and tested backup and recovery procedures. It's the difference between a vendor saying "we take security seriously" and a CPA firm confirming, on evidence, that they did so every day of the audit period.

Verify It Yourself

Security claims should be checkable. Our current SOC 2 report and the full picture of our security practices are always available through our Trust Center, and you can read more about our approach on our security page. If your security team needs the report for a vendor review, they can request access there directly.