Sapeum has completed a SOC 2 Type 2 examination. The audit was performed by Sensiba LLP, an independent public accounting firm. The resulting report is available to customers and prospective customers on request, under a non-disclosure agreement.
What a SOC 2 Type 2 report covers
SOC 2 is an attestation report rather than a certification. The distinction determines what the document can tell a reviewer. A certification records that an organization was assessed against a defined list of requirements and passed. An attestation records that an independent auditor examined the controls an organization describes, tested them, and reported the results, including any exceptions identified during testing.
The difference between a Type 1 and a Type 2 report is the period of observation. A Type 1 report addresses whether controls are suitably designed at a single point in time. A Type 2 report addresses whether those controls operated effectively across a defined period, with the auditor sampling evidence throughout that period and reporting on how the controls performed in practice.
The report is written by the auditor rather than by us. It sets out the controls that were in scope, the procedures performed against each of them, and the auditor's opinion on the results. That is what makes it usable as evidence in a review, and it is also why the document runs to considerably more than a summary page.
Why this matters for our customers
Sapeum captures how an organization actually operates: its steps, handoffs, exceptions, and the operational knowledge its people hold but have never written down. That material is sensitive by nature, and it frequently falls within a customer's own regulatory and contractual obligations.
A Type 2 report gives a risk team an independent basis for assessing how that material is handled. It replaces our account of our own controls with an auditor's tested findings, which is the standard of evidence enterprise security reviews are built to expect.
Requesting the report
If Sapeum is under evaluation as a vendor, the report is intended to support that review. Contact your account team and we will provide it under an NDA. A SOC 2 report contains detailed descriptions of an organization's controls and of the auditor's testing procedures, so it is not published publicly.
SOC 2 Type 2 is a recurring commitment rather than a one-time exercise. Each report covers a defined window, and organizations reviewing a vendor expect to be looking at a current one.
Our security practices, subprocessor list, and supporting documentation are available at trust.sapeum.com.