Wonder how this will mesh with Vanta’s new Trust Report feature.
All it current requires is an agreement and your email address.
The Trust Report doesn’t show all the details unless you configure it to show those details.
All it current requires is an agreement and your email address.
The Trust Report doesn’t show all the details unless you configure it to show those details.
SOC2 broadly contains:
- A description of what the company claims to do
- A statement that the description is complete and accurate
- Auditor's testing procedure for verifying the company's claims
- The results of the testing
- The auditor's overall conclusion as to whether the company meets the bar for SOC2.
Trust Report seems to only cover the first point.The Trust Reports contain programmatically-validated information (basically: Vanta's code says the control was in place continuously.)
There's (obviously) pros and cons of trusting a software provider (like Vanta) to validate technical configuration compared to trusting a human auditor to do the same.
Our bet with Trust Reports is that for some cases, having software do the checking and validation continuously is better than having a human auditor do it once a year.