Advertise on KripZen — put your brand in front of a global crypto audience.Get in touch →

Glossary entry

SOC 2 Report

Wallets & Security

A SOC 2 report is a controls audit, not a reserve audit. What Type 1 and Type 2 actually test, and why a SOC 2 badge tells you nothing about whether the coins are there.

Definition

A SOC 2 report is an attestation produced by an independent accounting firm about whether an organisation's internal controls meet a defined set of criteria covering security and, optionally, availability, processing integrity, confidentiality and privacy. A Type 1 report says the controls were suitably designed on one date. A Type 2 report says they also operated effectively across a period, usually somewhere between three and twelve months, and is the more meaningful of the two by a wide margin. Crypto exchanges cite SOC 2 constantly, and it is worth having: it means someone outside the company checked that access is restricted, that changes are reviewed, that incidents get logged and that the described process is the process actually followed. What it emphatically does not do is count anything. A SOC 2 report makes no statement about whether customer balances are fully backed, where the coins sit, or whether the exchange is solvent — that question belongs to proof-of-reserves and proof-of-liabilities work, which is a different exercise with a different scope. Two further cautions. The badge on a website is not the report; the report itself is usually only released under a confidentiality agreement, and the scope section is where you learn which systems were in it. And an attestation covers a past window, so a report is a statement about the year that ended, not the platform you are depositing into today.

Next

Related terms

More in Wallets & Security