Type II Attested
Held continuously since 2021.
SOC 2 Type II controls continuously attested since 2021, 99.97% uptime across the last 36 months, and 2.1 million monthly field events processed without a single incident — all available for review under NDA before your security team signs off.
Used on 11,400+ active projects across 47 U.S. states and 19 countries · Trusted by 9 of the ENR Top 400 contractors.
The certifications your procurement team scans for — listed the way a stamp-block on a drawing sheet lists them, with the year it was first issued.
Held continuously since 2021.
In production since 2022.
Controls in place since 2022.
Penetration tested annually by Curia Labs.
"SOC 2" is the audit credential a CFO recognizes; "what does it actually do for our project" is what your project executive will ask on the demo call. Here is the operational translation.
Every drawing upload, redline, and markup is tied to a named user, a session, an IP range, and a timestamp — logged to a write-once bucket with 7-year retention. If a subcontractor opens Sheet A-301 from a café in Cleveland at 06:42, your IT team can tell you exactly what was viewed and exported.
No code reaches production without a peer-reviewed merge, an automated test pass, and a documented approver. The same control covers your tenant configuration — workflow edits, permission changes, and integration token rotations are recorded for the audit window.
Our Type II window never closes — a Big Four firm tests controls continuously and re-issues the report every quarter. The letter on file is never older than 90 days, which is the answer your security reviewer wants before signing.
The most recent test was completed on 2024-11-08 by Curia Labs, covering web app, API (120+ endpoints), and infrastructure. Critical findings SLA: 14 days to remediate or document compensating control — and the SLA itself has held on every prior cycle.
Four frameworks, one row each, with the controls and the documents that satisfy a procurement reviewer’s first pass.
Type II attestation covering all three TSCs. Continuous monitoring, annual penetration test, quarterly letters on file.
SCCs in place, EU-Frankfurt residency available, 30-day DSAR turnaround SLA, and a contracted DPO.
All 93 Annex A controls mapped in our Statement of Applicability. Formal certification tracking through 2025.
Mapped to Identify, Protect, Detect, Respond, Recover, and the new Govern function. Aligned with federal procurement standards.
Most procurement questionnaires land before the demo call. Here are the answers, in the order they tend to come up, so the call starts with architecture instead of paperwork.
Pick the one that matches your role: a live demo with the security brief included, or the public uptime artifact you can hand to procurement today.
Walk through your project workflows with someone who has run a $40M build. The SOC 2 Type II report, the latest penetration-test summary, and the uptime PDF are bundled into the calendar invite under NDA.
Book a Demo → Avg. first response: 4h 12m · Mon–Fri 7am–7pm CTThe same uptime record our status page publishes, packaged as a printable PDF. Shareable with anyone on your procurement checklist — no NDA required.
Request Uptime PDF Window covered: Nov 2021 – Nov 2024 · 99.97%