Trust / SOC 2

SOC 2 at AxisSynapse

AxisSynapse is built for a SOC 2 Type II examination against the AICPA Trust Services Criteria. Our controls are enforced continuously — by build-blocking CI gates and an immutable, hash-chained audit trail — which is exactly the operating effectiveness a Type II auditor samples across the observation period.

Trust Services Criteria in scope

Security (Common Criteria)
CC1–CC9 — the baseline every SOC 2 report covers.
Availability
A1 — uptime commitments, capacity, backup + tested DR.
Confidentiality
C1 — classification, retention, and disposal of confidential data.
Processing Integrity
PI1 — complete, accurate, timely processing.
Privacy
P1–P8 — notice, choice, collection, retention, and disposal of personal information.
Observation period

Our Type II observation window and auditor are published here once the examination is scheduled. A bridge letter is available between reports.

Request the report

The full report is shared under NDA. Email security@axissynapse.com with your entity name.

How we make the evidence turnkey

Every technical control maps to the SOC 2 criteria it satisfies in a machine-readable catalog, and a continuous evidence bundle keys each control to the CI gate that proves it on every build. See our Trust Center and public status page.

Related: Subprocessors · DPA · Vulnerability disclosure