SOC 2 Type II Certified Security Controls

SOC 2 Type II is an independent audit framework developed by the American Institute of Certified Public Accountants (AICPA). It evaluates whether an organization's security controls are designed effectively and operate consistently over time.

SOC 2 assessments are based on the Trust Services Criteria, which include Security, Availability, Processing Integrity, Confidentiality, and Privacy. Unlike a Type I report, a Type II report evaluates how these controls perform over an extended audit period.

TeamSync undergoes regular SOC 2 Type II assessments to help customers evaluate the security and operational controls protecting their information.

What SOC 2 Covers

  • TSC 2017 (revised 2022): Common criteria that apply across all categories, plus criteria specific to each category

  • Common criteria (CC1–CC9): Control environment, communication and information, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, and risk mitigation

  • Additional criteria: Availability (A1.1–A1.3), Processing Integrity (PI1.1–PI1.5), Confidentiality (C1.1–C1.2), and Privacy (P1–P8)

  • Type II: Operating effectiveness over the full audit period, attested by an independent CPA firm

How TeamSync Supports SOC 2 Compliance

1. An annual SOC 2 Type II report
TeamSync's SOC 2 Type II report covers the Security, Availability, Confidentiality, and Privacy trust services criteria, and is available under NDA.

2. Continuous control monitoring
Controls are evidenced on an ongoing basis rather than rebuilt right before the audit, which reduces the usual scramble at audit time.

3. Handling of sub-service organisations
Sub-service organisations, such as cloud infrastructure providers, are covered using either the inclusive method or the carve-out method, as documented in the report.

4. Customer-facing documentation
Includes the SOC 2 Type II report, a bridge letter to cover any inter-period gap, a control summary, a sub-processor list, and a security whitepaper.

5. Access for customer auditors
Customer auditors can review the report and ask follow-up questions, in line with the criteria set for user entities in the report.

What Customers Get

Aspect

TeamSync coverage

Security TSC

Covered

Availability TSC

Covered

Confidentiality TSC

Covered

Privacy TSC

Covered

Processing Integrity TSC

Selectable per scope

Type II report

Annual

Bridge letter

Available

Sub-processor list

Maintained

  • SOC 1: Financial-reporting controls, covered under a separate report

  • SOC 3: The public-summary version of SOC 2

  • ISO 27001:2022: The international parallel

  • HITRUST CSF: The healthcare-extended equivalent

Who This Page Is For

  • CISO (cross-vertical)

  • CISO and Audit Committee