Skip to main content
Compliance and Privacy

SOC 2 Compliance

A security framework for service organizations developed by the AICPA, requiring controls around security, availability, confidentiality, and privacy of customer data.

SOC 2 (System and Organization Controls 2) is a compliance framework developed by the American Institute of CPAs (AICPA). It evaluates how well a service organization manages customer data based on five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

SOC 2 compliance is increasingly required by enterprise customers before they’ll trust a vendor with their data. The audit examines policies, procedures, and technical controls over a period of time (Type II) or at a point in time (Type I).

Password management is directly relevant to SOC 2: auditors examine how credentials are stored, shared, rotated, and logged. Using a team password manager with access controls and audit trails helps demonstrate the controls SOC 2 requires.

Back to the glossary

Stop sharing passwords in spreadsheets

TeamPassword stores, shares and rotates your team credentials, encrypted end to end.

Trusted by 900+ agencies and small teams worldwide