Is there an entity that can validate they are not SOC2 compliant outside of their claim?
Yes, SOC2 require an audit by an independent auditor, and in principle you can request their audit report from them.
Just email the CTO about it ;)
Yes, SOC2 require an audit by an independent auditor, and in principle you can request their audit report from them.
Just email the CTO about it ;)