SOC 2 is an AICPA attestation framework that reports on how a service organization’s controls protect customer data across five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is the only mandatory criterion; the other four are included based on the commitments a company makes to its customers.
OfficeRnD has completed its annual assessment and obtained a clean SOC 2 Type 2 report on the examination of controls relevant to Security, Availability, Confidentiality, and Privacy using predefined criteria in TSP section 100, Trust Services Criteria for the period of July 1, 2022, to June 30, 2023, as we look to demonstrate our continuous commitment to security and data privacy.
The SOC 2 audit was conducted by leading compliance assessor A-LIGN, a technology-enabled security and compliance company trusted by more than 6,400 organizations worldwide to help mitigate cybersecurity risks.

As we obtained our previous SOC 2 report in 2022 we committed to our clients that we will undergo the assessment on an annual basis. By completing this year’s assessment, we did not only do that but we built upon our already robust security posture and included additional controls over the 300 controls we had in our previous report. This independent assessment of our internal security controls highlights our commitment to maintaining the highest standards of security for our diverse and global customer base and continuously improving upon it – Deyan Varchev, Chief Technology Officer at OfficeRnD
Established by the American Institute of Certified Public Accountants (AICPA), the examination is designed for organizations of any size, regardless of industry and scope, to ensure the personal assets of their potential and existing customers are protected. SOC 2 reports are recognized globally and affirm that a company’s infrastructure, software, people, data, policies, procedures and operations have been formally reviewed.
“A SOC 2 audit is a statement about an organization’s commitment to protecting their information.” said Stephanie Oyler-Rankin, SOC Practice Lead at A-LIGN. “As a trusted third-party assessment firm, A-LIGN independently evaluates client data processes and procedures, governance on internal controls and security posture. OfficeRnD’s SOC 2 report validates its commitment to data security and protection, as well as compliance with critical standards to mitigate cybersecurity threats.”
OfficeRnD keeps its commitment to perform a SOC 2 assessment on an annual basis and can make the report available to current or potential customers upon execution of a non-disclosure agreement. If you are interested in viewing our SOC 2 report, please contact our security team at [email protected].
A SOC 2 Type 2 report evaluates whether a company’s controls are suitably designed and operating effectively over a defined period, rather than at a single point in time. A Type 1 report validates the design of controls at one moment; a Type 2 report proves operational effectiveness over a period that typically runs 3 to 12 months, and is increasingly the standard enterprise customers require.
No. SOC 2 results in an attestation report issued by a licensed CPA firm, not a certificate. The report includes the auditor’s opinion on the controls in place for each Trust Services Criteria that a company chooses to include in scope.
SOC 2 reports cover a defined period and are renewed annually. A report is generally considered valid for 12 months, which is why organizations undergo the examination each year to maintain continuous coverage. OfficeRnD completes its SOC 2 assessment on an annual basis.
OfficeRnD makes its SOC 2 report available to current and prospective customers after signing a non-disclosure agreement. Contact the security team at [email protected] to request access.