Cycle achieves SOC 2 Type 1: Strengthening our commitment to data security and system availability

Cycle recently went through a System and Organization Controls (SOC) 2 Type 1 audit and we've got the report. It’s an important step in our continuous commitment to data security and system availability. But are we just checking boxes for the sake of boxes or is there more behind it?

cycle gear darkThe Cycle Team
4 Min Read
soc2_security_image_clear_background

Cycle recently went through a System and Organization Controls (SOC) 2 Type 1 audit and we've got the report. It’s an important step in our continuous commitment to data security and system availability. But are we just checking boxes for the sake of boxes or is there more behind it?

We think security and uptime is as important to our customers as they are to us. We think in terms of security and resilience from the first step we take on any project, to the point where we don't even allow AI to touch any code for our core platform – that stuff has to be as bulletproof as we can make it. From field-level encryption on all sensitive data to our atomic read-only operating system (CycleOS), we've met or exceeded the technical requirements for several standards but we also think it’s time we simplify the compliance process for companies out there, shortening the due diligence process by having the evidence available for review.

Simplifying adoption for teams with compliance requirements

Saying we’re committed to compliance is one thing and long time customers know we mean it. But for companies working in regulated industries knowing sometimes isn't enough. You need a certain framework around proving it and a shared language with your compliance organization that ultimately might be the gatekeeper to using Cycle.

SOC 2 can help because it is a defined and well known internationally recognized standard with controls for what the American Institute of Certified Public Accountants calls Trust Services Criteria. Among them are three groups that we hold in the highest regard; Security, Availability, and Confidentiality. 

The principals and practices aren’t new to us, we’ve had the policies and worked this way since the beginning. But this is our first SOC 2 report so as part of the process we mapped the SOC 2 controls to our policies, practices and processes ensuring that we adhere to this framework that allows an independent auditor to come in and assess and attest to our adherence to that standard, generating a report that you and your compliance and risk management team can review.

The difference between Type 1 and Type 2

Now there is a Type 1 and a Type 2 and Cycle has completed Type 1, a kind of a point-in-time assessment of our controls, policies and processes; the first milestone; confirming that the policies and controls around how we do what we do, our ways of working, are appropriate for the relevant AICPA Trust Services Criteria.

Type 2 is different in that it assesses whether the controls we have in place are operationally effective over a defined period of time, so some time has to pass between the Type 1 and the Type 2 reports. We are now in that monitoring phase and compliance with internationally recognized standards will continue to be our goal.

Continuous verification is the goal

So are we just checking boxes for the sake of boxes? Well, honestly there is no way around the fact that when you adhere to a certain framework there is some level of adjusting to fit the standard, checking the box so to speak, but we don't believe that is a bad thing.

We believe that having an available SOC 2 report that customers and prospects can review and utilize in their own security, vendor-management and procurement processes is of great value and it establishes a chain of trust – kind of like a TLS certificates chain, but for Security, Availability and Confidentiality controls. We also had a 3rd party, Ambaga, complete a thorough penetration test of our systems as part of the process and at the risk of blowing our own horn we received some feedback we are pretty proud of, among it in relation to our approach to Access Control Lists:

"Delivering streamlined design alongside a serious security mindset usually takes an enterprise-sized team. Seeing a lean crew pull it off so effectively is impressive."
Bergsteinn Karlsson
Bergsteinn Karlsson
CEO and Co-founder//Ambaga

So no, we aren’t just checking boxes – this is part of our core.

Please don't hesitate to reach out to us via cycle.io/contact for a copy of the report.

Cookies

Cookies Preferences

We run basic, anonymous analytics by default to measure site traffic. By clicking "Accept," you allow additional cookies for advanced app improvements and tailored advertising. Choose what you share by clicking "Customize."