# What SOC 2 Type 2 Means for Portfolio Data

> Octav is SOC 2 Type 1 and Type 2 compliant. What the difference actually is, what auditors test, and why it matters when a vendor reads your fund's wallets.

- **URL:** https://octav.fi/blog/soc2-type-2-certified
- **Published:** 2026-07-12
- **Author:** Octav Team — Portfolio Intelligence for Digital Assets
- **Topic:** NAV Reporting
- **Tags:** security, compliance, soc2
- **Source:** Octav, Practical guides on crypto NAV reporting, multi-chain portfolio management and digital asset APIs, from the team behind Octav.

---
**Octav is SOC 2 Type 1 and Type 2 compliant.** Evidence is published at
[trust.octav.fi](https://trust.octav.fi).

Most vendors that say "SOC 2" mean Type 1. The difference is the whole point of
the standard, and it is worth understanding before you accept either as an
answer.

## Type 1 vs Type 2

| | SOC 2 Type 1 | SOC 2 Type 2 |
| --- | --- | --- |
| Question | Are the controls *designed* correctly? | Did the controls *actually operate*? |
| Evidence | A snapshot on one date | Continuous evidence over a window |
| Window | A point in time | Typically 6–12 months |
| Analogy | The fire exits are in the right places | The fire drills were run, logged and passed |

Type 1 says a control exists on paper on the day the auditor looked. Type 2
says an independent auditor sampled evidence across months and confirmed the
control ran every time it was supposed to.

Only one of those tells you what happens on an ordinary Tuesday when nobody is
watching.

## What the auditor actually tests

SOC 2 is organised around five Trust Services Criteria. Security is mandatory;
the others are included based on what the service does.

| Criterion | Examples of what gets tested |
| --- | --- |
| **Security** | Access control, change management, encryption, incident response |
| **Availability** | Monitoring, capacity planning, disaster recovery |
| **Confidentiality** | Data classification, retention, disposal |
| **Processing integrity** | Data is complete, valid and timely |
| **Privacy** | Handling of personal information |

For a portfolio data provider, **confidentiality** is the criterion that should
interest you most, and for a reason specific to this category: your positions
are public on-chain, but *the mapping from your fund to a set of addresses is
not*. That mapping is exactly what a portfolio vendor holds. See
[Security Questions to Ask a Portfolio Vendor](/soc2-security-portfolio-data).

## Why this matters more here than for typical SaaS

Two properties compound:

**A portfolio provider sees your whole book.** Not one workflow — every
position, across every wallet you connect, including
[perps](/hyperliquid-perps-portfolio-tracking) and
[options](/derive-options-portfolio-tracking) that are otherwise hard to
observe from outside.

**The data feeds regulated reporting.** If a provider's output flows into
[NAV](/what-is-crypto-nav-reporting) or an audit pack, its control environment
becomes part of yours. Your auditor will ask about it, and "they have a badge
on their website" is not a sufficient answer.

## What SOC 2 does not tell you

Being straight about the limits, because a certification is often over-read:

- **It is not a guarantee against breach.** It attests that controls were
  designed and operating, not that nothing can ever go wrong.
- **Scope is chosen by the vendor.** A report can legitimately cover a narrow
  set of systems. Read the scope section, not the summary.
- **It says nothing about data quality.** SOC 2 will not tell you whether an
  API decodes Solana DeFi correctly. That is what
  [the benchmark](/crypto-portfolio-api-benchmark) is for.
- **The window has an end date.** A Type 2 report covers a past period. Ask when
  the current window closes and when the next report is due.

A compliance certificate and a correct portfolio are different assurances. You
need both, and they are audited by completely different people.

## How to use this in a vendor review

1. Ask for the **report**, not the badge — under NDA if necessary.
2. Check it is **Type 2**, and read the observation window.
3. Read the **scope**: which systems and which criteria.
4. Read the **exceptions** section. Every real report has some; a vendor that
   explains theirs is more credible than one that claims none.
5. Confirm the vendor is **read-only and never holds private keys** — for
   portfolio tracking this matters more than any certification, because it caps
   the worst case at disclosure rather than loss of funds.

Point five is the one people skip. SOC 2 tells you a vendor manages risk well.
Read-only access tells you the risk was small to begin with.

## Octav's position

- SOC 2 **Type 1 and Type 2** compliant.
- **Read-only.** Octav never asks for private keys and cannot move funds.
- **Passwordless authentication** via magic link — no password database.
- Public evidence at [trust.octav.fi](https://trust.octav.fi).

If your security team wants the report or has questions the Trust Center does
not answer, ask — that request should never be difficult.
