SOC 2 Type II Certified Security Controls
SOC 2 Type II is an independent audit framework developed by the American Institute of Certified Public Accountants (AICPA). It evaluates whether an organization's security controls are designed effectively and operate consistently over time.
SOC 2 assessments are based on the Trust Services Criteria, which include Security, Availability, Processing Integrity, Confidentiality, and Privacy. Unlike a Type I report, a Type II report evaluates how these controls perform over an extended audit period.
TeamSync undergoes regular SOC 2 Type II assessments to help customers evaluate the security and operational controls protecting their information.
What SOC 2 Covers
TSC 2017 (revised 2022): Common criteria that apply across all categories, plus criteria specific to each category
Common criteria (CC1–CC9): Control environment, communication and information, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, and risk mitigation
Additional criteria: Availability (A1.1–A1.3), Processing Integrity (PI1.1–PI1.5), Confidentiality (C1.1–C1.2), and Privacy (P1–P8)
Type II: Operating effectiveness over the full audit period, attested by an independent CPA firm
How TeamSync Supports SOC 2 Compliance
1. An annual SOC 2 Type II report
TeamSync's SOC 2 Type II report covers the Security, Availability, Confidentiality, and Privacy trust services criteria, and is available under NDA.
2. Continuous control monitoring
Controls are evidenced on an ongoing basis rather than rebuilt right before the audit, which reduces the usual scramble at audit time.
3. Handling of sub-service organisations
Sub-service organisations, such as cloud infrastructure providers, are covered using either the inclusive method or the carve-out method, as documented in the report.
4. Customer-facing documentation
Includes the SOC 2 Type II report, a bridge letter to cover any inter-period gap, a control summary, a sub-processor list, and a security whitepaper.
5. Access for customer auditors
Customer auditors can review the report and ask follow-up questions, in line with the criteria set for user entities in the report.
What Customers Get
Aspect | TeamSync coverage |
Security TSC | Covered |
Availability TSC | Covered |
Confidentiality TSC | Covered |
Privacy TSC | Covered |
Processing Integrity TSC | Selectable per scope |
Type II report | Annual |
Bridge letter | Available |
Sub-processor list | Maintained |
Related Rules And Frameworks
SOC 1: Financial-reporting controls, covered under a separate report
SOC 3: The public-summary version of SOC 2
ISO 27001:2022: The international parallel
HITRUST CSF: The healthcare-extended equivalent
Who This Page Is For
CISO (cross-vertical)
CISO and Audit Committee