Sapeum has completed its SOC 2 Type 2 audit

Sensiba LLP has examined and tested how Sapeum protects customer data across a defined period. Here is what the report covers and how to request it.

The Sapeum team

2 min read

Sapeum has completed a SOC 2 Type 2 examination. The audit was performed by Sensiba LLP, an independent public accounting firm. The resulting report is available to customers and prospective customers on request, under a non-disclosure agreement.

What a SOC 2 Type 2 report covers

SOC 2 is an attestation report rather than a certification. The distinction determines what the document can tell a reviewer. A certification records that an organization was assessed against a defined list of requirements and passed. An attestation records that an independent auditor examined the controls an organization describes, tested them, and reported the results, including any exceptions identified during testing.

The difference between a Type 1 and a Type 2 report is the period of observation. A Type 1 report addresses whether controls are suitably designed at a single point in time. A Type 2 report addresses whether those controls operated effectively across a defined period, with the auditor sampling evidence throughout that period and reporting on how the controls performed in practice.

The report is written by the auditor rather than by us. It sets out the controls that were in scope, the procedures performed against each of them, and the auditor's opinion on the results. That is what makes it usable as evidence in a review, and it is also why the document runs to considerably more than a summary page.

Why this matters for our customers

Sapeum captures how an organization actually operates: its steps, handoffs, exceptions, and the operational knowledge its people hold but have never written down. That material is sensitive by nature, and it frequently falls within a customer's own regulatory and contractual obligations.

A Type 2 report gives a risk team an independent basis for assessing how that material is handled. It replaces our account of our own controls with an auditor's tested findings, which is the standard of evidence enterprise security reviews are built to expect.

Requesting the report

If Sapeum is under evaluation as a vendor, the report is intended to support that review. Contact your account team and we will provide it under an NDA. A SOC 2 report contains detailed descriptions of an organization's controls and of the auditor's testing procedures, so it is not published publicly.

SOC 2 Type 2 is a recurring commitment rather than a one-time exercise. Each report covers a defined window, and organizations reviewing a vendor expect to be looking at a current one.

Our security practices, subprocessor list, and supporting documentation are available at trust.sapeum.com.

Share

Keep reading

More from the blog

All posts
Perspectives 8 min read

The Hidden Cost of Undocumented Work

Undocumented work creates delays, fragile handoffs, weak ownership, and leadership blind spots. Making workflows visible is a prerequisite for scaling, accountability, and AI readiness.

Read the post The Sapeum team

See it on your own process

Bring a workflow to a 30-minute session and watch it become a living process map — captured, redesigned, and ready to govern.

Request a demo