logoalt Hacker News

petcatyesterday at 12:20 PM1 replyview on HN

There are typically two soc2 reports generated from an audit. The first is the one for general use, often just shared publicly. This is probably what you look at from public companies that you have no binding relationship with. The other is the restricted use report which details all the findings and controls. That is typically only shared under NDA.


Replies

mgraczykyesterday at 12:48 PM

I haven't seen that and all the reports I got were under nda