Audited

SOC 2 Type II Compliant Virtual Inspection Software

Independently audited security, availability, and confidentiality controls.

SOC 2 Type II is the gold-standard security audit for SaaS platforms handling sensitive customer data. Unlike Type I — which reviews controls at a single point in time — a Type II report evaluates the operating effectiveness of those controls over a sustained observation window (typically 6–12 months) by an independent CPA firm.

What SOC 2 Type II Actually Verifies

The audit examines five Trust Services Criteria defined by the AICPA. Virtual Inspection Pro is scoped against the criteria most relevant to inspection data:

  • Security — protection against unauthorized access, disclosure, and system damage

  • Availability — system uptime, monitoring, incident response, and disaster recovery

  • Confidentiality — protection of information designated as confidential (inspection media, PII, reports)

  • Processing Integrity — complete, valid, accurate, timely, and authorized data processing

  • Privacy — collection, use, retention, disclosure, and disposal of personal information

Why It Matters for Virtual Inspections

Every photo, video, GPS coordinate, and signed report captured through VIP flows through infrastructure covered by our SOC 2 program. That means access controls, encryption keys, change management, employee onboarding, vendor management, and incident response are all continuously audited — not self-attested.

Controls Enforced in the Platform

SOC 2 isn't paperwork. It maps to enforcement inside the product:

  • Role-based access with least-privilege defaults

  • MFA enforcement for administrative and elevated access

  • Full audit logs of every read, write, share, and export

  • Encryption in transit (TLS 1.3) and at rest (AES-256)

  • Continuous vulnerability scanning and monitored intrusion detection

  • Documented incident response with defined SLAs

Frequently asked

Can I request a copy of your SOC 2 Type II report?

Yes. Enterprise customers and prospects under NDA can request the current report through their account manager.

How often is the audit refreshed?

Annually, with a continuous monitoring program between formal audits.

Talk to sales

Need documentation for procurement?

Enterprise customers can request reports, questionnaires, and DPAs through their account manager or by contacting our security team directly.

Get started

Ready to run your first virtual inspection?

See verified remote capture in action, or dive straight into pricing built for teams that inspect at scale.

Privacy