Not SOC 2 certified — readiness in progress

SMPL is pursuing SOC 2 Type I. We are not “SOC 2 compliant” or “SOC 2 certified” until an independent CPA firm issues a report. This page tracks readiness work only.

Trust · Security

SOC 2 readiness

Honest progress toward SOC 2 Type I. We are not certified until an independent CPA firm issues a report.

Last updated 2026-07-22 · statuses live in frontend/lib/compliance/progress.ts

Current focus: Matt: MFA on all admin cloud accounts (Week 1) — then no shared passwords + protect main

Scope APPROVED 2026-07-22 by Matt Justice: Security + Availability + Confidentiality IN; Processing Integrity and Privacy DEFERRED. All roles: Matt Justice.

What “done” means

An independent CPA firm has issued a SOC 2 Type I report covering Security + Availability + Confidentiality, and that report is in hand (typically shared with customers under NDA).

Say “SOC 2 readiness in progress” or “we are pursuing SOC 2.” Never say “we are SOC 2 certified” until a report exists.

Remaining & targets

Solo-founder calendar — realistic targets, not commitments. Type I is “compliant” only when the CPA report is in hand.

Not certified

Target calendar

  1. Week 1 (now)

    ~2026-07-22 → 2026-07-29

    MFA on all admin accounts; confirm no shared prod passwords; protect main + required PR review if not done

  2. Week 2

    ~2026-07-29 → 2026-08-05

    Approve DRAFT policies P01–P12 (or core set); platform decision (Vanta wait date or signup)

  3. Week 3–4

    ~2026-08-05 → 2026-08-19

    Access review #1 signed; backup restore test evidence; IR tabletop notes; vendor SOC collection started; DPA legal path

  4. Month 2

    ~2026-08-19 → 2026-09-19

    Controls habitually running; secrets spot-check; tenant isolation evidence; AI/LLM write-up finalized; security one-pager published for sales

  5. Month 3–4

    ~2026-09-19 → 2026-11-19

    Engage CPA / Type I fieldwork TARGET (adjustable — not a commitment)

  6. After Type I

    Report in hand + 3–12 months

    Type II observation window, then Type II report

Remaining checklist

StatusItemOwnerTarget
Needs ownerMFA — GitHub org adminsEvidence: screenshot or platform — do nextMattWeek 1
Needs ownerMFA — VercelMattWeek 1
Needs ownerMFA — RailwayMattWeek 1
Needs ownerMFA — NeonMattWeek 1
Needs ownerMFA — corporate email / IdPMattWeek 1
Needs ownerMFA — StripeMattWeek 1
Needs ownerMFA — Sanity (if admin)MattWeek 1
Needs ownerMFA — Resend / Anthropic consolesMattWeek 1
Needs ownerConfirm no shared prod passwordsMattWeek 1
Needs ownerProtect main + required PR reviewConfirm in GitHub settingsMattWeek 1
Needs ownerLeadership approve core policies (P01–P12 / core set)Draft ≠ approvedMattWeek 2
Needs ownerCompliance platform choice or “wait until ____”Do not stall MFA; no auto-signupMattWeek 2
Needs ownerConfirm boundary matches productionMattWeek 2–3
Needs ownerConfirm vendor regions / unused vendors; OpenAI if liveMattWeek 2–3
OpenFirst quarterly-style access review sign-offAfter MFA verified + inventory stableMattWeek 3–4
OpenNeon backup restore test evidenceMattWeek 3–4
OpenIR tabletop notes (operable IR)MattWeek 3–4
OpenVendor SOC / ISO reports — collection startedMattWeek 3–4
Needs ownerCustomer DPA — legal review / shipMattWeek 3–4
OpenSecrets only in env stores (spot-check)MattMonth 2
OpenTenant isolation evidence (Org A ≠ Org B)MattMonth 2
OpenAI/LLM / Anthropic subprocessor write-upMattMonth 2
OpenSecurity one-pager published for salesDraft existsMattMonth 2
Needs ownerTarget Type I month (YYYY-MM)TARGET, not commitmentMattMonth 2–3
Needs ownerAudit firm shortlist / engagementIndependent CPA — TARGET fieldworkMattMonth 3–4
Needs ownerEngage CPA; schedule Type I fieldworkTARGET, not commitmentMattMonth 3–4
OpenType I report issued → only then Type I is “done”Matt + CPAWhen report in hand
OpenType II observation (3–12 months) + Type II reportMatt + CPAAfter Type I

Readiness

33%

16 done · 4 in progress · 18 needs owner · 17 open (55 items). In-progress counts half toward the percentage.

Phase map

Phase 1

In progress

Kickoff

Scope APPROVED + owners named; scoreboard live — platform / target month / CPA still open

Phase 2

Open

Controls live

Policies approved; MFA + access inventory; change/deploy path; IR; restore test; vendor evidence; tenant isolation evidence

Phase 3

Open

Type I audit

CPA firm engaged; fieldwork complete; Type I report issued

Phase 4

Open

Type II

Controls operate cleanly over observation window; Type II report issued

Done~In progress!Needs ownerOpen

A. Kickoff & governance

Plan, owners, decision log, and engagement framing.

77%

10/13 done · 3 need owner

  • kg-1Kickoff plan publisheddocs/SOC2_TYPE1_KICKOFF.mdDone
  • kg-2Readiness reference (scope + criteria)docs/SMPL_SOC2_Readiness_Reference_v2.mdDone
  • kg-3Working folder docs/soc2/ seededDecision log, boundary, subprocessors, access template, policy indexDone
  • kg-4Progress scoreboard createddocs/soc2/PROGRESS.md + this pageDone
  • kg-5Decision log — scope + owners APPROVEDSec+Avail+Conf IN; PI + Privacy DEFERRED; all owners Matt Justice (2026-07-22 APPROVED)Done
  • kg-6Freeze Type I criteria: Sec + Avail + Conf; PI deferred; Privacy skipAPPROVED in decision log 2026-07-22Done
  • kg-7Name executive sponsorMatt JusticeDone
  • kg-8Name security ownerMatt JusticeDone
  • kg-9Name engineering ownerMatt Justice (all roles for now)Done
  • kg-10Name ops / CS privileged-access ownerMatt Justice (all roles for now)Done
  • !kg-11Compliance platform choice or explicit “wait until ____”TBD — Matt to decide (Week 2). Do not auto-sign up for VantaNeeds owner
  • !kg-12Target Type I monthEven approximate YYYY-MM — TARGET, not commitmentNeeds owner
  • !kg-13Audit firm shortlist / engagementIndependent CPA; platform partner network OK laterNeeds owner

B. System boundary & vendors

What is in scope and which vendors process customer data.

38%

3/8 done · 3 need owner

  • bv-1System boundary draft from known stackVercel, Railway, Neon, Auth.js, Resend, Anthropic, Stripe, GitHub, SanityDone
  • ~bv-2Boundary TBDs assignedSanity in/out, staging, hostnames, OpenAI fallback, privileged opsIn progress
  • !bv-3Confirm boundary matches productionNeeds owner
  • bv-4Subprocessors named list draftDone
  • !bv-5Confirm regions / unused vendors; mark OpenAI if liveNeeds owner
  • bv-6Vendor SOC / ISO reports folder (under NDA)Open
  • !bv-7Customer DPA — legal review / shipNeeds owner
  • bv-8Security one-pagerdocs/soc2/SECURITY_ONE_PAGER.md — draft done; publish for sales = Month 2Done

C. Access hardening

MFA everywhere admins live, plus a living access inventory.

0%

0/11 done · 9 need owner

  • !ah-1MFA — GitHub org adminsWeek 1 — do nextNeeds owner
  • !ah-2MFA — VercelWeek 1Needs owner
  • !ah-3MFA — RailwayWeek 1Needs owner
  • !ah-4MFA — NeonWeek 1Needs owner
  • !ah-5MFA — corporate email / IdPWeek 1Needs owner
  • !ah-6MFA — StripeWeek 1Needs owner
  • !ah-7MFA — Sanity (if admin)Week 1Needs owner
  • !ah-8MFA — Resend / Anthropic consolesWeek 1Needs owner
  • ~ah-9Access inventory — people + roles filledMatt on all known systems; MFA verified unchecked — needs MattIn progress
  • !ah-10Confirm no shared prod passwordsWeek 1Needs owner
  • ah-11First quarterly-style access review sign-offAfter MFA verified + inventory stable — Week 3–4Open

D. Policies

Written controls — drafts exist; leadership approval still required.

50%

2/4 done · 1 need owner

  • pol-1Policy indexDone
  • pol-2Draft stubs expanded: ISP, Acceptable Use, Access Control, IR, Change MgmtP01–P05 DRAFT / not approvedDone
  • ~pol-3Remaining core policies (P06–P17)P06, P08, P09, P11, P12 drafted; P07/P10/P13–P17 openIn progress
  • !pol-4Leadership approve core policiesDraft ≠ approved; Matt must approve — Week 2Needs owner

E. Engineering hygiene

Branch protection, deploy path, secrets, restore test, tenant isolation.

17%

1/6 done · 1 need owner

  • !eng-1Protect main + required PR reviewConfirm in GitHub settings — Week 1Needs owner
  • eng-2Document deploy path (Vercel FE, Railway API) + who can promotedocs/soc2/CHANGE_MANAGEMENT.mdDone
  • eng-3Secrets only in env stores (not git)Month 2Open
  • eng-4Calendar or complete Neon backup restore testEvidence required before Type I — Week 3–4Open
  • eng-5Tenant isolation evidence (Org A ≠ Org B)Month 2Open
  • eng-6AI/LLM data-handling write-up aligned with P15Month 2Open

F. Pre–Type I readiness bar

Book the auditor only when these controls are live, not merely drafted.

0%

0/9 done

  • bar-1MFA on admin/cloud accountsOpen
  • bar-2Written policies approved by leadershipOpen
  • bar-3Access inventory + first review artifactOpen
  • ~bar-4Documented change/deploy path + PR review on mainPath documented; PR protection still needs MattIn progress
  • bar-5Incident response plan (approved + operable)Draft exists; not approvedOpen
  • bar-6Backup restore test evidenceOpen
  • bar-7Subprocessor inventory + vendor reports collectedInventory draft; reports not collectedOpen
  • bar-8Tenant isolation evidenceOpen
  • bar-9AI/subprocessor write-up for AnthropicOpen

G. Type I → Type II

Engagement, report issuance, then observation window.

0%

0/4 done · 1 need owner

  • !t12-1Engage CPA firm; schedule fieldworkTARGET Month 3–4Needs owner
  • t12-2Type I report issued → this is when Type I is “done”Open
  • t12-3Keep controls operating; start Type II observation clockOpen
  • t12-4Type II report issuedOpen

Detailed internal scoreboard: docs/soc2/PROGRESS.md