Not SOC 2 certified — readiness in progress
SMPL is pursuing SOC 2 Type I. We are not “SOC 2 compliant” or “SOC 2 certified” until an independent CPA firm issues a report. This page tracks readiness work only.
Trust · Security
SOC 2 readiness
Honest progress toward SOC 2 Type I. We are not certified until an independent CPA firm issues a report.
Last updated 2026-07-22 · statuses live in frontend/lib/compliance/progress.ts
Current focus: Matt: MFA on all admin cloud accounts (Week 1) — then no shared passwords + protect main
Scope APPROVED 2026-07-22 by Matt Justice: Security + Availability + Confidentiality IN; Processing Integrity and Privacy DEFERRED. All roles: Matt Justice.
What “done” means
An independent CPA firm has issued a SOC 2 Type I report covering Security + Availability + Confidentiality, and that report is in hand (typically shared with customers under NDA).
Say “SOC 2 readiness in progress” or “we are pursuing SOC 2.” Never say “we are SOC 2 certified” until a report exists.
Remaining & targets
Solo-founder calendar — realistic targets, not commitments. Type I is “compliant” only when the CPA report is in hand.
Not certified
Target calendar
Week 1 (now)
~2026-07-22 → 2026-07-29
MFA on all admin accounts; confirm no shared prod passwords; protect main + required PR review if not done
Week 2
~2026-07-29 → 2026-08-05
Approve DRAFT policies P01–P12 (or core set); platform decision (Vanta wait date or signup)
Week 3–4
~2026-08-05 → 2026-08-19
Access review #1 signed; backup restore test evidence; IR tabletop notes; vendor SOC collection started; DPA legal path
Month 2
~2026-08-19 → 2026-09-19
Controls habitually running; secrets spot-check; tenant isolation evidence; AI/LLM write-up finalized; security one-pager published for sales
Month 3–4
~2026-09-19 → 2026-11-19
Engage CPA / Type I fieldwork TARGET (adjustable — not a commitment)
After Type I
Report in hand + 3–12 months
Type II observation window, then Type II report
Remaining checklist
| Status | Item | Owner | Target |
|---|---|---|---|
| Needs owner | MFA — GitHub org adminsEvidence: screenshot or platform — do next | Matt | Week 1 |
| Needs owner | MFA — Vercel | Matt | Week 1 |
| Needs owner | MFA — Railway | Matt | Week 1 |
| Needs owner | MFA — Neon | Matt | Week 1 |
| Needs owner | MFA — corporate email / IdP | Matt | Week 1 |
| Needs owner | MFA — Stripe | Matt | Week 1 |
| Needs owner | MFA — Sanity (if admin) | Matt | Week 1 |
| Needs owner | MFA — Resend / Anthropic consoles | Matt | Week 1 |
| Needs owner | Confirm no shared prod passwords | Matt | Week 1 |
| Needs owner | Protect main + required PR reviewConfirm in GitHub settings | Matt | Week 1 |
| Needs owner | Leadership approve core policies (P01–P12 / core set)Draft ≠ approved | Matt | Week 2 |
| Needs owner | Compliance platform choice or “wait until ____”Do not stall MFA; no auto-signup | Matt | Week 2 |
| Needs owner | Confirm boundary matches production | Matt | Week 2–3 |
| Needs owner | Confirm vendor regions / unused vendors; OpenAI if live | Matt | Week 2–3 |
| Open | First quarterly-style access review sign-offAfter MFA verified + inventory stable | Matt | Week 3–4 |
| Open | Neon backup restore test evidence | Matt | Week 3–4 |
| Open | IR tabletop notes (operable IR) | Matt | Week 3–4 |
| Open | Vendor SOC / ISO reports — collection started | Matt | Week 3–4 |
| Needs owner | Customer DPA — legal review / ship | Matt | Week 3–4 |
| Open | Secrets only in env stores (spot-check) | Matt | Month 2 |
| Open | Tenant isolation evidence (Org A ≠ Org B) | Matt | Month 2 |
| Open | AI/LLM / Anthropic subprocessor write-up | Matt | Month 2 |
| Open | Security one-pager published for salesDraft exists | Matt | Month 2 |
| Needs owner | Target Type I month (YYYY-MM)TARGET, not commitment | Matt | Month 2–3 |
| Needs owner | Audit firm shortlist / engagementIndependent CPA — TARGET fieldwork | Matt | Month 3–4 |
| Needs owner | Engage CPA; schedule Type I fieldworkTARGET, not commitment | Matt | Month 3–4 |
| Open | Type I report issued → only then Type I is “done” | Matt + CPA | When report in hand |
| Open | Type II observation (3–12 months) + Type II report | Matt + CPA | After Type I |
Readiness
33%
16 done · 4 in progress · 18 needs owner · 17 open (55 items). In-progress counts half toward the percentage.
Phase map
Phase 1
In progressKickoff
Scope APPROVED + owners named; scoreboard live — platform / target month / CPA still open
Phase 2
OpenControls live
Policies approved; MFA + access inventory; change/deploy path; IR; restore test; vendor evidence; tenant isolation evidence
Phase 3
OpenType I audit
CPA firm engaged; fieldwork complete; Type I report issued
Phase 4
OpenType II
Controls operate cleanly over observation window; Type II report issued
A. Kickoff & governance
Plan, owners, decision log, and engagement framing.
77%
10/13 done · 3 need owner
- ✓
kg-1Kickoff plan publisheddocs/SOC2_TYPE1_KICKOFF.mdDone - ✓
kg-2Readiness reference (scope + criteria)docs/SMPL_SOC2_Readiness_Reference_v2.mdDone - ✓
kg-3Working folder docs/soc2/ seededDecision log, boundary, subprocessors, access template, policy indexDone - ✓
kg-4Progress scoreboard createddocs/soc2/PROGRESS.md + this pageDone - ✓
kg-5Decision log — scope + owners APPROVEDSec+Avail+Conf IN; PI + Privacy DEFERRED; all owners Matt Justice (2026-07-22 APPROVED)Done - ✓
kg-6Freeze Type I criteria: Sec + Avail + Conf; PI deferred; Privacy skipAPPROVED in decision log 2026-07-22Done - ✓
kg-7Name executive sponsorMatt JusticeDone - ✓
kg-8Name security ownerMatt JusticeDone - ✓
kg-9Name engineering ownerMatt Justice (all roles for now)Done - ✓
kg-10Name ops / CS privileged-access ownerMatt Justice (all roles for now)Done - !
kg-11Compliance platform choice or explicit “wait until ____”TBD — Matt to decide (Week 2). Do not auto-sign up for VantaNeeds owner - !
kg-12Target Type I monthEven approximate YYYY-MM — TARGET, not commitmentNeeds owner - !
kg-13Audit firm shortlist / engagementIndependent CPA; platform partner network OK laterNeeds owner
B. System boundary & vendors
What is in scope and which vendors process customer data.
38%
3/8 done · 3 need owner
- ✓
bv-1System boundary draft from known stackVercel, Railway, Neon, Auth.js, Resend, Anthropic, Stripe, GitHub, SanityDone - ~
bv-2Boundary TBDs assignedSanity in/out, staging, hostnames, OpenAI fallback, privileged opsIn progress - !
bv-3Confirm boundary matches productionNeeds owner - ✓
bv-4Subprocessors named list draftDone - !
bv-5Confirm regions / unused vendors; mark OpenAI if liveNeeds owner bv-6Vendor SOC / ISO reports folder (under NDA)Open- !
bv-7Customer DPA — legal review / shipNeeds owner - ✓
bv-8Security one-pagerdocs/soc2/SECURITY_ONE_PAGER.md — draft done; publish for sales = Month 2Done
C. Access hardening
MFA everywhere admins live, plus a living access inventory.
0%
0/11 done · 9 need owner
- !
ah-1MFA — GitHub org adminsWeek 1 — do nextNeeds owner - !
ah-2MFA — VercelWeek 1Needs owner - !
ah-3MFA — RailwayWeek 1Needs owner - !
ah-4MFA — NeonWeek 1Needs owner - !
ah-5MFA — corporate email / IdPWeek 1Needs owner - !
ah-6MFA — StripeWeek 1Needs owner - !
ah-7MFA — Sanity (if admin)Week 1Needs owner - !
ah-8MFA — Resend / Anthropic consolesWeek 1Needs owner - ~
ah-9Access inventory — people + roles filledMatt on all known systems; MFA verified unchecked — needs MattIn progress - !
ah-10Confirm no shared prod passwordsWeek 1Needs owner ah-11First quarterly-style access review sign-offAfter MFA verified + inventory stable — Week 3–4Open
D. Policies
Written controls — drafts exist; leadership approval still required.
50%
2/4 done · 1 need owner
- ✓
pol-1Policy indexDone - ✓
pol-2Draft stubs expanded: ISP, Acceptable Use, Access Control, IR, Change MgmtP01–P05 DRAFT / not approvedDone - ~
pol-3Remaining core policies (P06–P17)P06, P08, P09, P11, P12 drafted; P07/P10/P13–P17 openIn progress - !
pol-4Leadership approve core policiesDraft ≠ approved; Matt must approve — Week 2Needs owner
E. Engineering hygiene
Branch protection, deploy path, secrets, restore test, tenant isolation.
17%
1/6 done · 1 need owner
- !
eng-1Protect main + required PR reviewConfirm in GitHub settings — Week 1Needs owner - ✓
eng-2Document deploy path (Vercel FE, Railway API) + who can promotedocs/soc2/CHANGE_MANAGEMENT.mdDone eng-3Secrets only in env stores (not git)Month 2Openeng-4Calendar or complete Neon backup restore testEvidence required before Type I — Week 3–4Openeng-5Tenant isolation evidence (Org A ≠ Org B)Month 2Openeng-6AI/LLM data-handling write-up aligned with P15Month 2Open
F. Pre–Type I readiness bar
Book the auditor only when these controls are live, not merely drafted.
0%
0/9 done
bar-1MFA on admin/cloud accountsOpenbar-2Written policies approved by leadershipOpenbar-3Access inventory + first review artifactOpen- ~
bar-4Documented change/deploy path + PR review on mainPath documented; PR protection still needs MattIn progress bar-5Incident response plan (approved + operable)Draft exists; not approvedOpenbar-6Backup restore test evidenceOpenbar-7Subprocessor inventory + vendor reports collectedInventory draft; reports not collectedOpenbar-8Tenant isolation evidenceOpenbar-9AI/subprocessor write-up for AnthropicOpen
G. Type I → Type II
Engagement, report issuance, then observation window.
0%
0/4 done · 1 need owner
- !
t12-1Engage CPA firm; schedule fieldworkTARGET Month 3–4Needs owner t12-2Type I report issued → this is when Type I is “done”Opent12-3Keep controls operating; start Type II observation clockOpent12-4Type II report issuedOpen
Detailed internal scoreboard: docs/soc2/PROGRESS.md