Audited
SOC 2 Type II Compliant Virtual Inspection Software
Independently audited security, availability, and confidentiality controls.
SOC 2 Type II is the gold-standard security audit for SaaS platforms handling sensitive customer data. Unlike Type I — which reviews controls at a single point in time — a Type II report evaluates the operating effectiveness of those controls over a sustained observation window (typically 6–12 months) by an independent CPA firm.
What SOC 2 Type II Actually Verifies
The audit examines five Trust Services Criteria defined by the AICPA. Virtual Inspection Pro is scoped against the criteria most relevant to inspection data:
Security — protection against unauthorized access, disclosure, and system damage
Availability — system uptime, monitoring, incident response, and disaster recovery
Confidentiality — protection of information designated as confidential (inspection media, PII, reports)
Processing Integrity — complete, valid, accurate, timely, and authorized data processing
Privacy — collection, use, retention, disclosure, and disposal of personal information
Why It Matters for Virtual Inspections
Every photo, video, GPS coordinate, and signed report captured through VIP flows through infrastructure covered by our SOC 2 program. That means access controls, encryption keys, change management, employee onboarding, vendor management, and incident response are all continuously audited — not self-attested.
Controls Enforced in the Platform
SOC 2 isn't paperwork. It maps to enforcement inside the product:
Role-based access with least-privilege defaults
MFA enforcement for administrative and elevated access
Full audit logs of every read, write, share, and export
Encryption in transit (TLS 1.3) and at rest (AES-256)
Continuous vulnerability scanning and monitored intrusion detection
Documented incident response with defined SLAs
Frequently asked
Can I request a copy of your SOC 2 Type II report?
Yes. Enterprise customers and prospects under NDA can request the current report through their account manager.
How often is the audit refreshed?
Annually, with a continuous monitoring program between formal audits.
Talk to sales
Need documentation for procurement?
Enterprise customers can request reports, questionnaires, and DPAs through their account manager or by contacting our security team directly.