SOC 2 Type II
Security underpins everything you run on Gallium. SOC 2 Type II is the independent auditing standard we use to demonstrate that the controls protecting the platform, and the data it holds, operate effectively over time.
What SOC 2 Type II Is
SOC 2 is an auditing framework from the American Institute of Certified Public Accountants (AICPA). It evaluates a service organization's controls against the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
The difference between the two report types matters:
- Type I assesses whether controls are suitably designed at a single point in time.
- Type II goes further: an independent auditor tests that those controls operated effectively across an extended observation period: typically several months to a year.
A Type II report is therefore evidence that security controls work in practice, not just on paper.
Gallium and SOC 2 Type II
Gallium maintains a SOC 2 Type II program covering the cloud platform that manages your infrastructure. Because the data inside your virtual machines stays on your own hypervisor hardware (see Data Locality), the customer data within the scope of the cloud audit is limited by design.
Requesting Our Report
Gallium's security and compliance information, including SOC 2, is available through the Gallium Trust Center.
Related
- Data Locality: what Gallium stores in the cloud versus on your hypervisor.
- License Programs: support and account management by program.