Book a demo Open the ROI calculator

[soc 2 type ii · 14-day trial · no card]

[trust center]

The security review, answered in writing.

What a procurement reviewer needs before anyone books a call: what the SOC 2 report covers, who processes the data, what the DPA says, and what happens when you leave.

[every value on this page is illustrative · the structure is the deliverable]

[audit artifacts]

What does the SOC 2 report cover?

[the mark]

SOC 2
TYPE II

[text lockup · not a seal · illustrative]

Rendered as type, deliberately. A real AICPA SOC badge requires registration, the unaltered downloaded asset, a hyperlink to aicpa.org/soc4so, and it expires twelve months after the report date. The ISO logo is never available for certification claims at all: the correct mark there is the certification body's own, with scope and certificate number. A demo that draws its own seal is teaching a licence violation, so this one does not.

Artifact list

[soc 2 type ii]

SOC 2 Type II report

Covers the Security, Availability, and Confidentiality trust services criteria for the Throughline platform and its supporting infrastructure. Type II means the auditor tested the controls across a period, not on one day.

[auditor]
Hartwell & Cole LLP, AICPA-registered CPA firm [illustrative]
[period]
2025-06 to 2026-05, twelve months
[jurisdiction]
United States, attested under AICPA standards

[pen test]

Annual penetration test

External network and web application, performed by an independent firm each spring. Findings above informational are remediated and retested before the letter is issued.

[performed by]
Corvid Assurance [illustrative]
[last test]
2026-03

[dpa]

Data processing agreement

GDPR Article 28 processor terms with the 2021 EU standard contractual clauses, modules two and three, and the UK addendum. Signable as presented; redlines go through legal like anywhere else.

[covers]
Processing purposes, security measures, subprocessor consent

[subprocessors]

Subprocessor record

Three vendors: cloud hosting, error monitoring, transactional email. The full table is below on this page, with region and a DPA link per vendor.

[change notice]
30 days before a new vendor processes customer data

[review pack]

Security review pack

The architecture summary, the answered questionnaire, the pen test letter, and the report request form in one folder, built to be forwarded into a committee.

[availability]
Network plan, or any procurement conversation

[subprocessors]

Who processes the data, and why?

Three vendors. None receives shipment contents beyond the alert text you configure.

Subprocessor list · illustrative vendor set · no partnership implied
Subprocessor Purpose Data category Region DPA
Amazon Web Services Cloud infrastructure and storage All customer data, encrypted at rest us-east-2 · eu-central-1 on Network AWS GDPR center
Sentry Error monitoring Stack traces and request metadata; shipment fields scrubbed US Sentry DPA
Postmark Transactional email Alert recipients, subject lines, message bodies US Postmark DPA

Additions get 30 days' notice before a new subprocessor touches customer data: an email to account owners and a dated entry on the record. Removals are logged in the same place. Read the full record with its change log.

[data ownership]

Who owns the data, and what happens on exit?

[ownership]
Yours, unambiguously.

Throughline is a processor under the DPA. Customer data is not used to train anything and is not shared beyond the subprocessors listed above.

[export]
CSV or Parquet, any time.

On every plan. Network adds read-only SQL access to your own workspace, so your BI tools query the data where it sits.

[termination]
30 days to export, then deletion.

On termination the workspace stays exportable for 30 days, then data is deleted with written confirmation.

[residency]
US by default, EU pinning on Network.

The region is set per workspace and recorded in the DPA annex. Data does not move between regions afterwards.

[retention]
Threads keep their history.

Exception threads stay queryable for the life of the account. Audit trails are immutable and export with everything else.

The same commitments in contract language: the DPA, the terms, and the privacy policy, which states the no-analytics decision in plain words.

[availability]

How often is it up?

[trailing 12 months]

99.972%

[trailing 90 days]

99.988%

[incidents · 12 months]

3

[longest incident]

41 min

[recovery point]

15 min

[recovery time]

4 h

[illustrative status data]

In a live trust center this strip reads from the status page and each incident links a dated postmortem. Network carries a 99.9% monthly uptime commitment with service credits; Team and Operations run on the same infrastructure without the contractual credit.

Book a demo

[bring your security questionnaire · answers land in writing]

[controls]

What does security look like in practice?

[the soc 2 evidence, in plain words]

  • [encryption]

    TLS 1.2+ in transit, AES-256 at rest

    Keys live in a managed KMS with annual rotation. Backups are encrypted with separate keys and restored quarterly as a drill, not only on the day it matters.

  • [sso]

    SSO / SAML

    Okta, Entra ID, and Google Workspace on Operations and up, with SCIM deprovisioning.

  • [rbac]

    Queue-level roles

    Read-only roles for finance and CS. Assign, resolve, and export are separate rights.

  • [access]

    Quarterly access reviews

    Production access is role-scoped and logged. The review is SOC 2 evidence, not a separate promise.

  • [incidents]

    72-hour notice

    Confirmed incidents touching customer data are notified within 72 hours, postmortem to follow.

[illustrative controls · the register a real page would use]

[the artifact beats the badge]

[next step]

Take the answers into the review.

Forward this page and the DPA to whoever signs. Bring what remains to the demo.