Revenue Contract Agent is in early access.
Meridian

Glossary

SOC 2 Type II

Definition

SOC 2 Type II is an independent auditor's report on how effectively a service organization's security and availability controls operated over a period.

SOC 2 reports are issued under the AICPA's Trust Services Criteria. A Type I report describes controls at a point in time; a Type II report tests whether they operated effectively over a period, typically 6 to 12 months. Buyers ask for Type II because it shows sustained operation rather than design alone.

The report covers criteria the vendor selects: security is mandatory, and availability, confidentiality, processing integrity, and privacy are optional. Reports are shared under NDA and should be read for scope, exceptions, and the auditor's opinion.

Meridian holds a SOC 2 Type II report covering security, availability, and confidentiality, available under NDA from the trust center.

All 34 terms

Get started

Put the first agent to work this quarter.

Start with one workflow, one approver, and one number to move. Most design partners were live in five weeks.