What is SOC 2?
The report larger customers ask for before they sign. Here is what it certifies, and what it asks of the product itself.
In short
SOC 2 is a report, written by an independent auditor, on whether a company's controls protect customer data, measured against the AICPA's criteria for security, availability, processing integrity, confidentiality and privacy. A Type 1 report checks the controls are designed properly at one date; a Type 2 report checks they actually worked over a period of months.
Also called: SOC 2 Type 1, SOC 2 Type 2, SOC 2 Type II
Why it matters when your prototype goes to production
Nobody needs SOC 2 to launch. It becomes urgent the week a larger customer sends a security questionnaire. Most of what the auditor examines is how the company operates: policies, access reviews, vendor management. But a good part is decided by how the product was built, and that part is expensive to retrofit.
The product side of SOC 2
- Access control: who can reach production data, enforced and reviewed.
- Audit logs: a record of who did what, kept and protected.
- Change management: every change reviewed, tested and released through a pipeline.
- Availability: monitoring, backups and a tested restore.
- MFA on every account that runs the product.
One misconception to avoid: your tools' reports do not cover your app. Lovable states it holds SOC 2 Type II, but that describes Lovable's controls, not the ones in the software you built with it.
Common questions
Do I need SOC 2?
When you sell to larger companies, especially in the US, you will be asked for it. Until then, build the product so that the controls exist when you need to show them.
Does SOC 2 cover GDPR?
No. SOC 2 is an audit report on security controls; GDPR is a law about personal data. They overlap in practice, but meeting one does not mean meeting the other.
Related terms
Read next
Sources
More on this: Production architecture & security · All glossary terms
Built something in Lovable you want people to rely on?
We are the engineers who take it the rest of the way — secured, tested, released and supported.