Yes, SOC2 require an audit by an independent auditor, and in principle you can request their audit report from them.
Just email the CTO about it ;)