What SOC 2 Type 2 Means for Portfolio Data
Octav is SOC 2 Type 1 and Type 2 compliant. What the difference actually is, what auditors test, and why it matters when a vendor reads your fund's wallets.

Octav is SOC 2 Type 1 and Type 2 compliant. Evidence is published at trust.octav.fi.
Most vendors that say "SOC 2" mean Type 1. The difference is the whole point of the standard, and it is worth understanding before you accept either as an answer.
Type 1 vs Type 2
| SOC 2 Type 1 | SOC 2 Type 2 | |
|---|---|---|
| Question | Are the controls designed correctly? | Did the controls actually operate? |
| Evidence | A snapshot on one date | Continuous evidence over a window |
| Window | A point in time | Typically 6–12 months |
| Analogy | The fire exits are in the right places | The fire drills were run, logged and passed |
Type 1 says a control exists on paper on the day the auditor looked. Type 2 says an independent auditor sampled evidence across months and confirmed the control ran every time it was supposed to.
Only one of those tells you what happens on an ordinary Tuesday when nobody is watching.
What the auditor actually tests
SOC 2 is organised around five Trust Services Criteria. Security is mandatory; the others are included based on what the service does.
| Criterion | Examples of what gets tested |
|---|---|
| Security | Access control, change management, encryption, incident response |
| Availability | Monitoring, capacity planning, disaster recovery |
| Confidentiality | Data classification, retention, disposal |
| Processing integrity | Data is complete, valid and timely |
| Privacy | Handling of personal information |
For a portfolio data provider, confidentiality is the criterion that should interest you most, and for a reason specific to this category: your positions are public on-chain, but the mapping from your fund to a set of addresses is not. That mapping is exactly what a portfolio vendor holds. See Security Questions to Ask a Portfolio Vendor.
Why this matters more here than for typical SaaS
Two properties compound:
A portfolio provider sees your whole book. Not one workflow — every position, across every wallet you connect, including perps and options that are otherwise hard to observe from outside.
The data feeds regulated reporting. If a provider's output flows into NAV or an audit pack, its control environment becomes part of yours. Your auditor will ask about it, and "they have a badge on their website" is not a sufficient answer.
What SOC 2 does not tell you
Being straight about the limits, because a certification is often over-read:
- It is not a guarantee against breach. It attests that controls were designed and operating, not that nothing can ever go wrong.
- Scope is chosen by the vendor. A report can legitimately cover a narrow set of systems. Read the scope section, not the summary.
- It says nothing about data quality. SOC 2 will not tell you whether an API decodes Solana DeFi correctly. That is what the benchmark is for.
- The window has an end date. A Type 2 report covers a past period. Ask when the current window closes and when the next report is due.
A compliance certificate and a correct portfolio are different assurances. You need both, and they are audited by completely different people.
How to use this in a vendor review
- Ask for the report, not the badge — under NDA if necessary.
- Check it is Type 2, and read the observation window.
- Read the scope: which systems and which criteria.
- Read the exceptions section. Every real report has some; a vendor that explains theirs is more credible than one that claims none.
- Confirm the vendor is read-only and never holds private keys — for portfolio tracking this matters more than any certification, because it caps the worst case at disclosure rather than loss of funds.
Point five is the one people skip. SOC 2 tells you a vendor manages risk well. Read-only access tells you the risk was small to begin with.
Octav's position
- SOC 2 Type 1 and Type 2 compliant.
- Read-only. Octav never asks for private keys and cannot move funds.
- Passwordless authentication via magic link — no password database.
- Public evidence at trust.octav.fi.
If your security team wants the report or has questions the Trust Center does not answer, ask — that request should never be difficult.
Keep reading
NAV ReportingSecurity Questions to Ask a Portfolio Vendor
What a fund's security review should cover before connecting wallets to a portfolio provider — key custody, read-only access, SOC 2 and data residency.
2 min read
NAV ReportingWhat Is NAV Reporting for Crypto Funds?
How digital asset funds calculate Net Asset Value across wallets, chains and DeFi protocols — and why manual spreadsheet NAV breaks at scale.
2 min read
NAV ReportingTransparency Dashboards for DeFi Treasuries
Public NAV and position pages let DAOs, vaults and treasuries prove holdings without granting access. What belongs on one and what to leave off.
2 min read