# soc 2

SOC 2 is a reporting and attestation framework for examining service-organization controls relevant to security, availability, processing integrity, confidentiality, and privacy.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## SOC 2 Controls for Non-Human Identities: CC6, CC7, and CC8

DevFeed: [SOC 2 Controls for Non-Human Identities: CC6, CC7, and CC8](<https://devfeed.tech/articles/soc-2-controls-for-non-human-identities-cc6-cc7-and-cc8-29856.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/soc2-non-human-identities/>)

Author: info@goteleport.com (Kayne McGladrey)

Published: 2026-06-09T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [soc 2](<https://devfeed.tech/topics/soc-2.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

This article explains how Teleport maps workload attestation, short-lived certificates, access rules, and audit logs for non-human identities to SOC 2 controls CC6, CC7, and CC8. It describes evidence auditors can use, including access rules, denied credential issuance logs, and Sigstore policy configurations where enabled.

### Source excerpt

Discover how to meet SOC 2 CC6, CC7, and CC8 controls for non-human identities.

## Multi-Site Data Center Audit and Compliance Best Practices

DevFeed: [Multi-Site Data Center Audit and Compliance Best Practices](<https://devfeed.tech/articles/multi-site-data-center-audit-and-compliance-best-practices-29619.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/data-center-compliance/>)

Author: info@goteleport.com (Mayur Pipaliya)

Published: 2026-05-11T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [datacenter](<https://devfeed.tech/topics/datacenter.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data-center](<https://devfeed.tech/tags/data-center.md>), [data-centers](<https://devfeed.tech/tags/data-centers.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [logging](<https://devfeed.tech/tags/logging.md>), [logs](<https://devfeed.tech/tags/logs.md>), [soc](<https://devfeed.tech/tags/soc.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

This article outlines audit and compliance challenges in multi-site data center environments, including fragmented logs, shared credentials, and weak identity attribution. It presents best practices for consistent audit visibility across sites.

### Source excerpt

Discover seven best practices for unified audit visibility and compliance across multi-site data centers.

## How AI Agents Impact SOC 2 Trust Services Criteria

DevFeed: [How AI Agents Impact SOC 2 Trust Services Criteria](<https://devfeed.tech/articles/how-ai-agents-impact-soc-2-trust-services-criteria-29560.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/ai-agents-soc-2/>)

Author: info@goteleport.com (Kayne McGladrey)

Published: 2026-02-25T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [soc 2 compliance](<https://devfeed.tech/topics/soc-2-compliance.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data](<https://devfeed.tech/tags/data.md>), [models](<https://devfeed.tech/tags/models.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [soc-2-compliance](<https://devfeed.tech/tags/soc-2-compliance.md>)

### AI overview

This article explains how agentic AI affects SOC 2 Trust Services Criteria. It maps SOC 2 requirements to autonomous systems and discusses controls for models, APIs, training data, automated decisions, AI outputs, and production execution records. It also outlines compliance challenges caused by autonomous actions and the need for effective, auditable oversight.

### Source excerpt

Learn how AI agents impact SOC 2 compliance and discover best practices for compliant agentic systems, models, and data.

## Laravel Cloud achieves SOC 2 Type 1 Compliance

DevFeed: [Laravel Cloud achieves SOC 2 Type 1 Compliance](<https://devfeed.tech/articles/laravel-cloud-achieves-soc-2-type-1-compliance-3755.md>)

Original publisher: [Read original article](<https://laravel.com/blog/laravel-cloud-achieves-soc-2-type-1-compliance>)

Author: André Valentin

Published: 2025-03-26T03:04:00Z

Content type: news

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [SOC](<https://devfeed.tech/topics/soc.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>), [Laravel](<https://devfeed.tech/topics/laravel.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [data](<https://devfeed.tech/topics/data.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [2](<https://devfeed.tech/tags/2.md>), [availability](<https://devfeed.tech/tags/availability.md>), [certifications](<https://devfeed.tech/tags/certifications.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data-protection](<https://devfeed.tech/tags/data-protection.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

Laravel Cloud has completed a SOC 2 Type 1 audit, confirming that its security controls are suitably designed and implemented at a specific point in time. The article explains the certification's implications for access protection, availability, confidentiality, privacy, and operational transparency, and notes plans for SOC 2 Type 2 certification and certifications for Laravel Forge and Laravel Nightwatch.

### Source excerpt

SOC 2 Type 1 compliance achieved with SOC 2 Type 2 coming soon for Laravel Cloud as well as Laravel Forge and Laravel Nightwatch.

## Teleport Achieves ISO 27001, HIPAA, and SOC 2 Compliance Milestones

DevFeed: [Teleport Achieves ISO 27001, HIPAA, and SOC 2 Compliance Milestones](<https://devfeed.tech/articles/teleport-achieves-iso-27001-hipaa-and-soc-2-compliance-milestones-29855.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/soc2-iso-27001-hipaa/>)

Author: reed@goteleport.com (Reed Loden)

Published: 2023-08-11T00:00:00Z

Content type: release

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [soc 2 compliance](<https://devfeed.tech/topics/soc-2-compliance.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>), [Security](<https://devfeed.tech/topics/security.md>), [trust](<https://devfeed.tech/topics/trust.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Availability](<https://devfeed.tech/topics/availability.md>)

Tags: [availability](<https://devfeed.tech/tags/availability.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [soc-2-compliance](<https://devfeed.tech/tags/soc-2-compliance.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

Teleport announces ISO 27001 certification, HIPAA compliance, and an expanded SOC 2 Type II report covering the Confidentiality and Availability trust service criteria.

### Source excerpt

An overview of Teleport Achieved ISO 27001, HIPAA, and SOC 2 Compliance Milestones

## Introducing the Apollo Trust Center

DevFeed: [Introducing the Apollo Trust Center](<https://devfeed.tech/articles/introducing-the-apollo-trust-center-23426.md>)

Original publisher: [Read original article](<https://www.apollographql.com/blog/introducing-the-apollo-trust-center>)

Author: Tad Whitaker

Published: 2023-02-07T08:35:00Z

Content type: release

Language: en

Sources: [Apollo Blog](<https://devfeed.tech/sources/apollo-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [GraphOS](<https://devfeed.tech/topics/graphos.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [announcement](<https://devfeed.tech/tags/announcement.md>), [backups](<https://devfeed.tech/tags/backups.md>), [customer-trust](<https://devfeed.tech/tags/customer-trust.md>), [download](<https://devfeed.tech/tags/download.md>), [gdpr](<https://devfeed.tech/tags/gdpr.md>), [graphos](<https://devfeed.tech/tags/graphos.md>), [registry](<https://devfeed.tech/tags/registry.md>), [reports](<https://devfeed.tech/tags/reports.md>), [routing](<https://devfeed.tech/tags/routing.md>), [security](<https://devfeed.tech/tags/security.md>), [security-compliance](<https://devfeed.tech/tags/security-compliance.md>), [soc](<https://devfeed.tech/tags/soc.md>), [trust-center](<https://devfeed.tech/tags/trust-center.md>)

### AI overview

Apollo launches the Apollo Trust Center, a centralized portal for security, compliance, reliability, and legal documentation. It includes SOC 2 reports, penetration-test summaries, security questionnaires, reliability metrics, and privacy-related legal materials.

### Source excerpt

Today, we're launching our new Trust Center, a single source of truth for Apollo's security, compliance, reliability, and legal documentation. Here's what you need to know. Understanding the Apollo Trust Center The Apollo Trust Center is for anyone with questions or needs concerning Apollo's compliance, security, reliability, or legal policies.

## Tinybird is SOC 2 Type II compliant

DevFeed: [Tinybird is SOC 2 Type II compliant](<https://devfeed.tech/articles/tinybird-is-soc-2-type-ii-compliant-18705.md>)

Original publisher: [Read original article](<https://www.tinybird.co/blog/tinybird-is-soc-2-type-ii>)

Author: Tinybird

Published: 2022-12-19T00:00:00Z

Content type: release

Language: en

Sources: [Tinybird](<https://devfeed.tech/sources/tinybird.md>)

Topics: [soc 2](<https://devfeed.tech/topics/soc-2.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [tinybird-news](<https://devfeed.tech/tags/tinybird-news.md>)

### AI overview

Tinybird announces that it is SOC 2 Type II certified, highlighting enterprise security and compliance.

### Source excerpt

Tinybird is SOC 2 Type II certified. Enterprise security without enterprise friction. Your compliance team will thank you.

## Security Milestone -- SOC 2 Type 2

DevFeed: [Security Milestone -- SOC 2 Type 2](<https://devfeed.tech/articles/security-milestone-soc-2-type-2-22927.md>)

Original publisher: [Read original article](<https://maestro.dev/blog/security-milestone-soc-2-type-2>)

Author: Leland Takamine

Published: 2022-12-08T08:00:00Z

Content type: article

Language: en

Sources: [mobile.dev - Medium](<https://devfeed.tech/sources/mobile-dev-medium.md>)

Topics: [soc 2](<https://devfeed.tech/topics/soc-2.md>), [SOC](<https://devfeed.tech/topics/soc.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [audit](<https://devfeed.tech/tags/audit.md>), [company](<https://devfeed.tech/tags/company.md>), [data](<https://devfeed.tech/tags/data.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [standards](<https://devfeed.tech/tags/standards.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

Maestro announces that it has issued a SOC 2 Type 2 Report following an external audit. The company says the report demonstrates that it is meeting its security commitments and describes it as a milestone in protecting users' data.

### Source excerpt

Today, we are excited to announce that we have issued our SOC 2 Type 2 Report.

## Tinybird announces SOC 2 Type 1 compliance and enterprise authentication support

DevFeed: [Tinybird announces SOC 2 Type 1 compliance and enterprise authentication support](<https://devfeed.tech/articles/big-security-updates-from-tinybird-18665.md>)

Original publisher: [Read original article](<https://www.tinybird.co/blog/soc-2-enterprise-authentication-announcement>)

Author: Tinybird

Published: 2022-07-14T00:00:00Z

Content type: release

Language: en

Sources: [Tinybird](<https://devfeed.tech/sources/tinybird.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [tinybird-news](<https://devfeed.tech/tags/tinybird-news.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

Tinybird announces SOC 2 Type 1 compliance and support for enterprise authentication.

### Source excerpt

Tinybird is now SOC 2 Type 1 compliant, plus we've added support for enterprise authentication.

## Good compliance programs don't require a fancy platform

DevFeed: [Good compliance programs don't require a fancy platform](<https://devfeed.tech/articles/good-compliance-programs-don-t-require-a-fancy-platform-35844.md>)

Original publisher: [Read original article](<https://temporal.io/blog/good-compliance-programs-do-not-require-a-fancy-platform>)

Author: Cully Wakelin

Published: 2021-10-18T07:00:00Z

Content type: opinion

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [soc 2](<https://devfeed.tech/topics/soc-2.md>), [trust](<https://devfeed.tech/topics/trust.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [customer-trust](<https://devfeed.tech/tags/customer-trust.md>), [doing](<https://devfeed.tech/tags/doing.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

This opinion article argues that effective compliance programs do not require sophisticated compliance automation platforms. It explains how frameworks such as SOC 2, HIPAA, and ISO 27001 help organizations establish customer trust, maintain best practices, identify gaps, and manage risk as they scale.

### Source excerpt

I would argue that the goal of any compliance effort--SOC 2, HIPAA, or ISO 27001--is the same: establishing customer trust.

## SOC 2 Certification - Table Stakes for B2B SaaS

DevFeed: [SOC 2 Certification - Table Stakes for B2B SaaS](<https://devfeed.tech/articles/soc-2-certification-table-stakes-for-b2b-saas-29854.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/soc2-certification-table-stakes-for-b2b-saas/>)

Author: info@goteleport.com (Travis Gary)

Published: 2020-07-29T00:00:00Z

Content type: opinion

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [soc 2](<https://devfeed.tech/topics/soc-2.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [on-prem](<https://devfeed.tech/topics/on-prem.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [b2b](<https://devfeed.tech/tags/b2b.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [on-prem](<https://devfeed.tech/tags/on-prem.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

Teleport explains what SOC 2 Type II certification involves and why it pursued certification for Teleport Cloud. The article contrasts compliance requirements for hosted SaaS with the trust and trade-offs of open source, self-hosted software, drawing on the company's own preparation experience.

### Source excerpt

We provide clarity on what SOC 2 is and what to expect from the certification process, based on our own experience preparing for the Teleport Cloud launch.