AICPA Trust Services Criteria

SOC 2 Type II — the only framework we audit.

We do not spread ourselves across dozens of frameworks. Skadi is built exclusively for SOC 2 Type II: deep coverage, faster evidence collection, and an independent audit report your enterprise buyers will trust.

See clients
4.9on Trustpilot
SOC 2 Type II Compliant
What is SOC 2 Type II?

A time-tested attestation report, not a checkbox certificate.

SOC 2 Type II reports on whether a service organization's controls are designed appropriately and operating effectively over a period of time. The report is governed by the AICPA Trust Services Criteria and is the standard SaaS and fintech companies need before enterprise customers will sign off on security reviews.

Observation period
3 — 12 months
Report type
Type II
Authority
Licensed CPA firm
Trust Services Criteria

One framework. Five criteria.

Security is required. Availability, Confidentiality, Processing Integrity, and Privacy are optional add-ons matched to your business and your customers' expectations.

Security

CC1 — CC9

The common criteria required for every SOC 2 report. Covers control environment, communication, risk assessment, monitoring, and system operations.

Availability

A1

Systems are available for operation and use as committed or agreed. Includes incident response, capacity planning, and performance monitoring.

Confidentiality

C1

Information designated as confidential is protected as committed or agreed. Covers identification, handling, retention, and disposal.

Processing Integrity

PI1

System processing is complete, valid, accurate, timely, and authorized. Often relevant for fintech, payment, and operations platforms.

Privacy

P1 — P7

Personal information is collected, used, retained, disclosed, and disposed of in conformity with commitments and criteria.

How it works

From onboarding to signed report.

A repeatable process that stays transparent at every step.

1

Pre-audit readiness

We run a pre-audit check against your systems, repositories, and GRC platform before the formal observation window begins.

2

Observation window

You choose 3, 6, or 12 months. Our AI continuously collects evidence, tests control operation, and flags exceptions in real time.

3

CPA review

A licensed CPA reviewer validates the evidence, tests exceptions, and makes the final professional judgments.

4

Signed report

You receive a peer-reviewed SOC 2 Type II report ready for enterprise procurement, VDRs, and customer security reviews.

From the tech ecosystem

Trusted by fast-moving technology companies.

Skadi is built for SaaS, fintech, AI infrastructure, and modern technology companies that need a focused SOC 2 Type II report.

Northwind
Fintech
Lumen
SaaS
Vertex
AI Infrastructure
Helix
DevTools
Kairos
Healthtech
Stellar
E-commerce
Arcadia
Cybersecurity
FAQ

SOC 2 Type II, explained.

Ready for a focused SOC 2 Type II audit?

Book a call and we'll walk you through the exact criteria, timeline, and scope for your company.

See clients