Skip to main content

Boardroom Answers · Strategic Command · Risk Management & Governance

SOC 2 vs ISO 27001: What Procurement Actually Requires

The question a Chairman of the Board / Audit Committee Chair asks: You have no SOC 2, no ISO 27001, and no external penetration test — and you are asking me to put board papers, the most sensitive documents this company produces, into your system. If that leaks, it is my signature on the approval. Give me one defensible reason to say yes.?

The short answer

No SOC 2, no ISO, no pen test yet — I’ll say it before you do. What exists is the thing certifications attest: CI-enforced isolation, KMS-backed encryption, hash-chained audit, inspectable under NDA. Dated milestones with contractual teeth close the gap; a staged pilot with non-privileged data is the honest shape of yes today.

The full executive answer

You are right on all three facts, and I will not soften them: no SOC 2, no ISO 27001, no completed external penetration test. Pre-launch, that is the truth, and any founder who blurs it should be shown the door. So let me make the only argument available to an honest vendor: the distinction your own profession draws between certification and control. A SOC 2 report is an auditor’s attestation that controls exist and operate; it is not the controls. What we have built — and what your security function can verify directly rather than take on faith — are the controls themselves, several of them enforced in ways an auditor would classify as automated, continuously operating: tenant isolation at the database layer with a CI test that fails our build if any customer-data table lacks a row-level-security policy; encryption of sensitive stored material through an AES-GCM vault keyed by AWS’s key-management service; an append-only, hash-chained audit log; quarterly-pattern access reviews; injection-screening and personal-data redaction on all untrusted text before it reaches any AI model; and secrets exclusively in server-side environment configuration with PII-masking in logging. Every push to production passes a five-stage gate including roughly 3,500 automated tests.

Now the roadmap, dated, because a gap without a closure plan is just a confession: external penetration test scheduled ahead of enterprise general availability — before, not after, we ask enterprises to trust us at scale; SOC 2 Type I targeted over the coming two to three quarters with Type II following its mandatory observation window; ISO 27001 sequenced after SOC 2 where customer geography demands it. On enterprise agreements I will contract these as milestones with remedies, so the commitment has teeth your committee can hold.

Finally, the defensible reason to say yes now rather than in a year, framed for your signature specifically: a staged engagement. Start in the free trial or Basic tier with non-privileged material — strategy diagnostics that do not touch board papers; let your security team inspect our controls under NDA, including the CI gates themselves; move privileged documents only when the pen-test and SOC 2 milestones land, per the contract. Your approval is then for a bounded, evidence-conditioned pilot — a decision your risk committee’s own third-party framework would classify as controlled experimentation, not exposure. That is the honest shape of yes, and if your answer to it is still no, that is a rational answer I will respect and revisit with the SOC 2 report in hand.

Grounded in: SOC 2 Trust Services Criteria (design vs operating effectiveness; certification vs control) · ISO/IEC 27001 (roadmap) · TPRM staged-engagement model

Want this answered live, on your data?