Third-party attestation covering security, availability, and confidentiality. The observation window is open. Auditor fieldwork and report issuance are targeted for Q4 2026. A readiness letter is available today on request.
SOC 2 is an attestation from a licensed CPA firm confirming that specific controls were operational during the observation period. A Type II report covers a sustained window (typically 6-12 months) and provides stronger assurance than a Type I (point-in-time).
Praktend engaged an auditor in 2026. The observation window is running now. The report itself will be issued once fieldwork closes, which we expect in Q4 2026. Until then, we can provide a readiness letter describing the controls in scope and their current operating status.
We are not yet SOC 2 Type II certified. If your procurement floor requires a current, issued Type II report, we do not have one today and we will tell you that straight.
These are the controls currently in the observation period. Status reflects current operational state, not auditor conclusions (those are not available until the report issues).
Role model enforces least-privilege. Two-axis identity separates app roles from per-company access.
LiveStructured audit log on every agent action and approval. Append-only, carrying an idempotency key and reversal pointer per write.
LiveFormal risk register and annual assessment process. Currently building documented process with assigned owners.
BuildingCentralized Cloud Logging on every Cloud Run service. Anomaly alerts on privileged actions in active build.
LiveAll production changes ship through CI with required code review. Pre-commit hooks block secrets and PII.
LiveRequired MFA on every operator account policy is building. Per-company data isolation is live at the Firestore rules layer.
BuildingAutomated daily backup to GCS. Cloud Run behind Firebase Hosting. No on-prem, no hand-rolled infrastructure.
LiveBranch-protected main. Feature branches require PR approval and passing CI before merge. Rollback runbooks in active build.
LiveVendor register with contract-time security review is in active build. Annual third-party security assessments planned for 2027.
BuildingCloud Run scales to zero and up automatically. Static assets on Firebase Hosting CDN. Uptime monitoring active.
LiveAES-256 at rest across Firestore, GCS, and Secret Manager. TLS 1.3 in transit on every public endpoint.
LiveCustomer-facing retention and deletion controls in build. PII scanner on every commit. Workspace BAA in force on every PHI flow.
BuildingThe report itself does not exist yet. The observation window is open and auditor fieldwork has not closed. We expect the report to issue in Q4 2026. If your procurement floor requires a current report today, we are not the right fit at this moment. We will say that directly rather than obscure it.
Email chris@praktend.com with your request. Turn-around noted below.
Send your questionnaire or procurement requirements. Reply within twenty-four hours.
Send a question →