✓ SOC 2 Type II

SOC 2 Type II Certification

Independent audit of our security, availability, and confidentiality controls

What is SOC 2?

Service Organization Control 2 (SOC 2) is a widely recognized auditing standard developed by the American Institute of CPAs (AICPA). It evaluates a service organization's non-financial reporting controls as they relate to the Trust Services Criteria.

Trust Services Criteria

quiXzoom's SOC 2 Type II audit covers the following principles:

🔒 Security

Protection against unauthorized access, use, or modification

📈 Availability

Systems available for operation and use as committed

🤝 Confidentiality

Confidential information protected as committed

🛡️ Processing Integrity

System processing complete, valid, accurate, and timely

Audit Scope

The SOC 2 Type II audit examines the effectiveness of controls over a period of time (minimum 6 months). quiXzoom's audit covers:

Key Controls

Access Control

Role-based access control (RBAC) with principle of least privilege. Multi-factor authentication (MFA) required for all production access. Regular access reviews quarterly.

Incident Response

24/7 monitoring with automated alerting. Incident response plan tested quarterly. Mean time to detect (MTTD): < 5 minutes. Mean time to respond (MTTR): < 1 hour.

Change Management

All changes require peer review and approval. Automated testing pipeline with 95%+ code coverage. Production deployments use blue-green deployment strategy.

Backup & Recovery

Automated daily backups with 30-day retention. Point-in-time recovery capability. Disaster recovery tested annually with RPO < 1 hour, RTO < 4 hours.

Audit Results

quiXzoom received an unqualified opinion (clean audit) with no exceptions noted. The audit was performed by an independent CPA firm specializing in SOC audits.

Audit Period

January 1, 2026 — June 30, 2026

Report Access

The SOC 2 Type II report is available to customers and partners under NDA. Contact our security team to request access.