Menu

Last updated: August 2026

How Do I Verify a Vendor's Security Claims?

Request the actual SOC 2 report — not just a badge on their website — and read the auditor's opinion section for any qualifications or exceptions. Ask for a recent penetration test summary, verify certification dates are current, and check for any public breach disclosures. A vendor unwilling to share this documentation directly, or one that only offers a logo and a paragraph of marketing copy, is itself a meaningful signal about how seriously they take the claim.

Why does the actual SOC 2 report matter more than the badge?

A "SOC 2 compliant" badge on a website is a marketing claim with no independent verification attached to the image itself. The actual SOC 2 report — typically 20-60 pages — includes the auditor's formal opinion, the specific Trust Service Criteria covered, the exact audit period, and critically, any exceptions or qualifications the auditor noted. A report with a "qualified opinion" or noted exceptions is meaningfully different from a clean report, and you can't tell the difference from a badge. Reputable vendors provide the report under a mutual NDA on request; a vendor that stalls indefinitely or won't produce it at all is not actually verifiable.

What should you check within the report itself?

Confirm it's Type II, not Type I — Type I only verifies controls were designed correctly at a single point in time, while Type II verifies they operated effectively over a sustained period (typically 6-12 months), which is a materially stronger claim. Check the audit period dates — a report covering a period ending 18 months ago tells you less about current practice than a recent one. Read which Trust Service Criteria are actually covered; Security is required in every SOC 2 report, but Availability, Confidentiality, Processing Integrity, and Privacy are each opted into separately, so confirm the criteria relevant to your specific concern are actually included.

What else should you ask for beyond the SOC 2 report?

Ask for a summary of their most recent penetration test — not necessarily the full technical report, but confirmation of when it was conducted, by whom, and at a high level what was found and remediated. Ask directly whether they've had any security incidents or data breaches in the past 2-3 years, and if so, how they were handled and disclosed. Search independently for any public breach disclosure or regulatory action involving the vendor rather than relying solely on their own account — public breach notification databases and news searches are a useful independent cross-check against what a vendor tells you directly.

Verification checklist

CheckRed flag
Request the full SOC 2 reportVendor stalls or only offers a badge/summary
Confirm Type II, not Type IVendor is vague about which type they hold
Check audit period recencyReport is over a year old with no renewal
Ask for recent pen test summaryNo recent test, or unwilling to discuss findings at all
Search independently for breach historyUndisclosed incidents found in public records

What Code Ninety does

Code Ninety provides its full SOC 2 Type II report directly to prospective clients on request under NDA, along with recent penetration test summaries, rather than pointing to a badge or logo as proof. Code Ninety publishes its cloud penetration testing results and security posture in full.

Related reading