Independent audit of our security, availability, and confidentiality controls
Service Organization Control 2 (SOC 2) is a widely recognized auditing standard developed by the American Institute of CPAs (AICPA). It evaluates a service organization's non-financial reporting controls as they relate to the Trust Services Criteria.
quiXzoom's SOC 2 Type II audit covers the following principles:
Protection against unauthorized access, use, or modification
Systems available for operation and use as committed
Confidential information protected as committed
System processing complete, valid, accurate, and timely
The SOC 2 Type II audit examines the effectiveness of controls over a period of time (minimum 6 months). quiXzoom's audit covers:
Role-based access control (RBAC) with principle of least privilege. Multi-factor authentication (MFA) required for all production access. Regular access reviews quarterly.
24/7 monitoring with automated alerting. Incident response plan tested quarterly. Mean time to detect (MTTD): < 5 minutes. Mean time to respond (MTTR): < 1 hour.
All changes require peer review and approval. Automated testing pipeline with 95%+ code coverage. Production deployments use blue-green deployment strategy.
Automated daily backups with 30-day retention. Point-in-time recovery capability. Disaster recovery tested annually with RPO < 1 hour, RTO < 4 hours.
quiXzoom received an unqualified opinion (clean audit) with no exceptions noted. The audit was performed by an independent CPA firm specializing in SOC audits.
January 1, 2026 — June 30, 2026
The SOC 2 Type II report is available to customers and partners under NDA. Contact our security team to request access.