How it plays out on a deal
Procurement and IT security teams at banks, law firms and listed companies routinely put this report on their vendor checklist, because a Type II opinion shows controls operating across months rather than on the day of the audit.
Scope is where reports differ. Some describe the vendor's product, people and processes; others lean on the cloud host's attestation for the data center layer, and any report may list auditor exceptions. Request the most recent copy, usually shared under a confidentiality agreement, and read the period, the systems in scope and the exceptions section.
What to check in a review or demo
- 1Whether the report is Type I or Type II, and the dates it covers.
- 2Whether it covers the data room application itself or only the hosting environment.
- 3Whether the auditor noted exceptions, and how the vendor responded.
SOC 2: where the reviewed providers stand
Based on the certifications and attestations each provider lists publicly, as recorded in our review data. Ask for the current report or certificate and check its scope before relying on it.
Yes (18)
ElltySOC 2 Infrastructure9.2/10
iDealsSOC 2 and ISO 270019.1/10
DatasiteSOC 2 and ISO 270018.9/10
AnsaradaSOC 2 and ISO 270018.6/10
IntralinksSOC 2 and ISO 270018.6/10
FirmexSOC 2 and ISO 270018.5/10
DroomsSOC 2 and ISO 270018.3/10
SmartRoomSOC 2 and ISO 270018.2/10
BoxSOC 2 and ISO 27001 and HIPAA8.1/10
Citrix ShareFileSOC 2 and ISO 27001 and HIPAA8.0/10
DealRoomSOC 2 and ISO 270018.0/10
CapLinkedSOC 27.7/10
SecureDocsSOC 27.7/10
ShareVaultSOC 2 and ISO 270017.7/10
OnehubSOC 27.5/10
Venue by DFINSOC 2 and ISO 270017.2/10
DigifySOC 26.9/10
DocSendSOC 26.6/10
No (0)
Every reviewed provider qualifies.
18 of 18 reviewed providers qualify. Each chip shows the provider's overall review score.
Read alongside
- ISO 27001ISO/IEC 27001 sets out how an organization should run its security program as a managed cycle of risk assessment, controls and review.
- Penetration testingA hired security team tries to break into the platform with the owner's permission, then reports the holes it found so they can be closed.
- HIPAAThe 1996 US federal law, with its Privacy and Security Rules, covering patient records held by health plans, providers and their vendors.
- Encryption at restScrambling stored files, backups included, so that anyone who walks off with a disk or a backup set gets unreadable data unless they also hold the keys.