SOC 2 Type I
An independent CPA firm, Vigil Assurance, PLLC, examined the design of our security controls for the kAudit system as of May 29, 2026.
What is SOC 2 Type I? SOC 2 is an audit framework from the AICPA. A Type I report evaluates whether security controls are suitably designed at a point in time.
Compliance Support
kAudit is built for teams needing to comply with SOC 2, HIPAA, PCI DSS, GLBA, GDPR, and SOX regulatory requirements. kAudit stores no PHI or PII and it helps you evidence change control over your databases without expanding your sensitive-data footprint.
kAudit supports
your compliance program; your organization remains responsible for its overall
compliance. Talk to us about how kAudit fits your specific framework.
Access & authentication
- Single sign-on via Microsoft Entra ID (organizational SSO).
- Role-based access control over portal actions — Viewer, Analyst, and Admin roles.
- Agent authentication via API key with Azure Key Vault-backed tokens; rotate keys from the portal without redeploying.
Encryption
- In transit: TLS 1.2 or higher on all connections.
- At rest: encrypted with Azure-managed keys, or your own customer-managed keys.
Infrastructure & Hosting
kAudit is hosted entirely on Microsoft Azure (US East region), deployed with infrastructure-as-code. Network access to service components is restricted to authorized endpoints via Azure networking policies. Azure's data centers are independently certified (ISO 27001, ISO 27017, ISO 27018, SOC 2), so kAudit runs on certified secure infrastructure.
Change management
Changes to production follow a documented change-management process: peer-reviewed code, approval before deployment, separated development / staging / production environments, and CI/CD pipeline controls.
Monitoring & Logging
Security and performance events are logged and monitored, and capacity, vulnerability, and backup conditions are monitored to support timely detection of and response to issues.
Incident Response
- Breach notification: if a confirmed security incident may affect your data, we notify you within 72 hours of becoming aware, share reasonable detail, and cooperate with required regulatory notification.
- Vulnerabilities: we use commercially reasonable
efforts to promptly remediate known critical- and high-severity
vulnerabilities.
People & Policies
- Personnel with production access are subject to background checks, confidentiality and IP obligations, and security-awareness training at hire and annually.
- Information-security policies are centralized and reviewed at least annually.
Shared Responsibility
Security is shared. kAudit secures the platform and its controls. Microsoft Azure secures the underlying infrastructure. You configure roles and access in your tenant, protect your credentials and API keys, and manage your own SQL Server environment. Our SOC 2 report describes the complementary controls we assume on your side.