SOC 2 Type 2 Compliance

SOC 2 Type 2, understood by your operations agent

The Hyphen SOC 2 Type 2 report is expected in Q4 2026. Agent maps the Trust Services Criteria, keeps evidence over the observation period, and does not issue a customer organization report.

Hyphen report expected Q4 2026 · 38 criteria · 4 automated · 18 reported · 16 remain with your team

Type 1, Type 2, and Hyphen's report

Type 2 is the observation period. Hyphen's report is expected in Q4 2026.

Buyers still hear Type 1, Type 2, and “are you certified?” used as if they were the same thing. They are not. Agent is built to gather Type 2 evidence that controls operated over time. Hyphen's own Type 2 examination is underway.

Point in time

SOC 2 Type 1

Design of controls on a single date.

A Type 1 report describes the system and opines on whether controls were suitably designed as of a date. Buyers still ask for it, then ask when Type 2 lands. It is not evidence that controls operated over time.

Current expectation

SOC 2 Type 2

Operating effectiveness over a period.

A Type 2 report tests whether controls actually ran over a period of typically three to twelve months. That is the report enterprise security questionnaires are waiting on.

Expected Q4 2026

Hyphen's Type 2

Examination in progress. Report under NDA.

Hyphen's own Type 2 examination is underway. The report is expected in Q4 2026. We will share it with customers under NDA once the independent auditor issues it. Until then, nothing on this page pretends the opinion already exists.

How Agent works the Type 2 period

Map. Operate. Report. Examine.

  1. 01

    Map the Trust Services Criteria

    Agent works from the Security, Availability, and Confidentiality categories of the 2017 Trust Services Criteria. That is the catalog a Type 2 observation period is measured against.

  2. 02

    Operate through the period

    Type 2 is not a snapshot. Agent keeps watching identity, deployments, secrets, flags, and infrastructure so evidence accumulates while the system is actually running.

  3. 03

    Collect evidence and report

    For criteria it cannot fully enforce, Agent gathers configuration, access, and activity evidence into a criterion-by-criterion view your auditor can read.

  4. 04

    A CPA issues the opinion. Agent does not.

    The Type 2 report is an independent auditor's opinion. Hyphen is not a CPA firm. Agent is the operational layer underneath the examination.

What Agent covers

Honest about the scope.

A Type 2 report tests whether controls operated over a period. Agent classifies each Trust Services Criterion as automate, report, or human so you can start the auditor conversation with organized evidence.

  • Knows the Type 2 catalog

    Every criterion in Security, Availability, and Confidentiality is named, family-mapped, and tagged for what Agent can automate, report, or leave with your people.

  • Automates the operating evidence

    4 criteria covering configuration monitoring, change management, and capacity can be enforced in the running system rather than reconstructed from screenshots.

  • Builds the evidence pack

    18 criteria get monitoring, configuration evidence, or partial implementation. The report shows what is in place, what is partial, and what still needs a person.

  • Leaves the human work honest

    16 criteria stay with governance, training, physical access, incident process, and vendor management. Agent will not pretend a board minute is a software problem.

Trust Services Criteria

38 criteria. Tagged for what Agent will do with each one.

Security, Availability, and Confidentiality from the 2017 Trust Services Criteria. Agent coverage is a planning view of what it can automate or put in an evidence report. It does not provide an auditor's opinion or Hyphen's Type 2 report.

  • 38criteria
  • 4automate
  • 18report
  • 16human
Trust Services Criteria families and how Agent covers each one
FamilyAutomateReportHumanTotal
Control Environment55
Communication and Information123
Risk Assessment224
Monitoring Activities22
Control Activities213
Logical and Physical Access628
System Operations2215
Change Management11
Risk Mitigation22
Availability1113
Confidentiality22

Agent automates4

Operating controls Agent can enforce through monitoring, change management, and capacity while the system is running.

System Operations2
  • CC7.1Detects configuration changes

    Infrastructure, software, and data are monitored to detect configuration changes and other anomalies that could affect objectives.

  • CC7.2Monitors system components

    System components are monitored for anomalies that are indicative of malicious acts, errors, and unusual events.

Change Management1
  • CC8.1Manages changes to the system

    Changes are authorized, designed, developed, configured, documented, tested, approved, and implemented, including infrastructure Agent proposes.

Availability1
  • A1.1Current processing capacity

    Current processing capacity and usage are maintained to enable the achievement of availability commitments.

Agent reports18

Criteria Agent can evidence, monitor, or help implement, with people and process still in the loop.

Communication and Information1
  • CC2.1Quality information

    The organization obtains or generates relevant, quality information to support the functioning of internal control.

Risk Assessment2
  • CC3.2Identifies risks

    Risks to the achievement of objectives, including security, are identified and analyzed as a basis for control design.

  • CC3.4Significant change

    Changes that could significantly affect the system of internal control are identified and assessed.

Monitoring Activities2
  • CC4.1Ongoing and separate evaluations

    Ongoing monitoring, separate evaluations, or both, are used to determine whether internal control is present and functioning.

  • CC4.2Communicates deficiencies

    Internal-control deficiencies are evaluated and communicated in time for those responsible to take corrective action.

Control Activities2
  • CC5.1Control activities that mitigate risk

    Control activities that contribute to the mitigation of risks to acceptable levels are selected and developed.

  • CC5.2Technology general controls

    General IT controls over the technology used to support the achievement of objectives are selected and developed.

Logical and Physical Access6
  • CC6.1Logical access security

    Logical access security software, infrastructure, and architectures restrict access to information assets and related assets.

  • CC6.2Registers and authorizes new users

    New internal and external users are registered, authorized, and issued credentials before they are granted system access.

  • CC6.3Removes access

    Access is removed when employment or the need for access ends, and credentials are recovered or disabled.

  • CC6.6Logical access security measures

    Logical access security measures protect against threats from sources outside the system boundaries.

  • CC6.7Restricts movement of information

    The transmission, movement, and removal of information are restricted to authorized users and processes.

  • CC6.8Prevents or detects malicious software

    Controls prevent or detect unauthorized or malicious software and unauthorized changes to known software.

System Operations2
  • CC7.3Evaluates security events

    Identified security events are evaluated to determine whether they could or have resulted in a failure to meet objectives.

  • CC7.5Identifies and implements recovery activities

    Activities to recover from identified security incidents are identified, developed, and implemented.

Availability1
  • A1.2Environmental protections and recovery

    Environmental protections, software, data backup, and recovery infrastructure are designed, developed, implemented, and operated.

Confidentiality2
  • C1.1Identifies confidential information

    Confidential information is identified and maintained throughout its collection, use, and retention to meet confidentiality commitments.

  • C1.2Disposes of confidential information

    Confidential information is disposed of in a manner that meets the entity's confidentiality commitments and system requirements.

Your team still owns16

Governance, physical access, incident process, and vendor management require human oversight.

Control Environment5
  • CC1.1Integrity and ethical values

    Leadership sets and demonstrates the standards of conduct the organization expects people to follow.

  • CC1.2Board oversight

    The board is independent of management and oversees internal control and the security program.

  • CC1.3Structure, reporting lines, and authority

    Management establishes reporting lines, authorities, and responsibilities for designing and operating controls.

  • CC1.4Commitment to competence

    The organization attracts, develops, and retains people with the competence the control environment requires.

  • CC1.5Accountability

    Individuals are held accountable for their internal-control responsibilities, including security.

Communication and Information2
  • CC2.2Internal communication

    Objectives, responsibilities, and security expectations are communicated internally so people can operate the controls.

  • CC2.3External communication

    Matters affecting the functioning of internal control are communicated to external parties, including customers and vendors.

Risk Assessment2
  • CC3.1Specified objectives

    Objectives are specified with enough clarity to identify and assess risks to their achievement.

  • CC3.3Fraud risk

    The organization considers the potential for fraud when assessing risks to the achievement of objectives.

Control Activities1
  • CC5.3Policies and procedures

    Control activities are deployed through policies that establish what is expected and procedures that put those policies into action.

Logical and Physical Access2
  • CC6.4Restricts access to physical assets

    Physical access to facilities, backup media, and other physical assets is restricted to authorized people.

  • CC6.5Discontinues physical access

    Physical access is discontinued when employment or the need for access ends.

System Operations1
  • CC7.4Responds to security incidents

    The organization responds to identified security incidents by executing a defined incident-response program.

Risk Mitigation2
  • CC9.1Identifies and selects risk mitigation

    Risk-mitigation activities are identified, selected, and developed as part of the risk-assessment process.

  • CC9.2Vendor and partner risk

    Risks associated with vendors and business partners are assessed and managed.

Availability1
  • A1.3Recovery plan testing

    Recovery plans are tested to help meet availability commitments in the event of an incident or disaster.

Frequently Asked Questions

Is Hyphen SOC 2 Type 2 certified today?

No. Hyphen's Type 2 examination is in progress, and the report is expected in Q4 2026. We will not describe Hyphen as SOC 2 Type 2 certified until that report is issued. When it is, we will share it with customers under NDA.

Does Hyphen Agent certify my company for SOC 2?

No. Only a licensed CPA firm can issue a SOC 2 report. Agent maps the Trust Services Criteria, automates technical safeguards, and produces evidence your team can hand to an auditor. Your organization still owns the system description, the control environment, and the relationship with the auditor.

What is the difference between SOC 2 Type 1 and Type 2?

Type 1 opines on the design of controls as of a point in time. Type 2 tests whether those controls operated effectively over an observation period, typically three to twelve months. Enterprise buyers almost always want Type 2. Agent is built for the Type 2 period: continuous evidence, not a one-day screenshot hunt.

Which Trust Services Criteria are in scope?

This page maps Security (the common criteria CC1–CC9), Availability (A1), and Confidentiality (C1). That is the set Hyphen's own Type 2 is expected to cover. Processing Integrity and Privacy are additional categories; Agent does not currently map them. Refer to the issued report for Hyphen's confirmed scope.

What can Agent automate versus only report?

Agent can automate 4 criteria that are enforced in the running system: detecting configuration changes, monitoring components, managing infrastructure changes with approval, and maintaining processing capacity. It reports on 18 more, including access control, encryption, logging review, and similar controls where it can collect evidence but cannot close the criterion alone. The remaining 16, including board oversight, physical access, incident process, and vendor management, stay with your people and facilities.

How do I request Hyphen's Type 2 report?

Create a Hyphen account or write to us once you are evaluating the platform. When the Q4 2026 report is issued, we will share it under NDA. Until then we can walk through security practices, the control catalog on this page, and the current examination status. The report will be available only after it is issued.

Will Agent change production systems to satisfy a criterion?

Not without approval. Agent starts read-only, proposes the change with evidence, and waits for a decision on sensitive work. Repository changes go through pull requests. Every action is logged, which is itself evidence for change-management and audit criteria.

Put the observation period in Agent's hands.

Connect your infrastructure. Agent maps the Trust Services Criteria, keeps evidence while the system runs, and leaves the opinion to a CPA.