Audit planned. Claims withheld.
We are working toward a SOC 2 Type II report. Until an auditor issues one, this page claims nothing, it shows where the engagement stands and which controls you can already assess. A standing request brings you the report the day it exists.
The road to a Type II, honestly drawn.
-
01 · Done
Controls designed & shipped
The mechanisms the criteria expect (isolation, filtered retrieval, the audit chain, the release gate) are in the product, not on a slide.
-
02 · In progress
Readiness & evidence
Evidence collection wired into the pipelines that already run: signed releases, heartbeats, audit exports, access records.
-
03 · Next
Observation window
The months a Type II is made of: the auditor watches controls operate, not a snapshot of them.
-
04 · Then
Report issued
The report lands with everyone whose request is standing, under NDA, as SOC 2 reports are.
No promised dates. The current engagement state is shareable at any time from your account.
The trust criteria, mapped to what runs.
Single-tenant isolation; permission filters inside every query; signed webhooks; per-IP backoff and challenges on sign-in; network-level intrusion ban lists at the managed edge
Signed heartbeats every 15 minutes with disturbance events; self-healing background jobs; safety backup before each update and automatic rollback on failed health checks
Write-only secrets; self-hosted AI keeps generation in-house, and the Naxis AI service runs zero-retention; no shared storage between clients; no AI-service keys on instances
Cite-or-abstain answers; deterministic date handling; a hash-chained audit log with one-click verification of the whole chain
Every row is expanded in the trust library and the architecture overview, reviewable before any auditor confirms it.
What to request, today and the day it lands.
No report exists yet and nothing is claimed until it does; the SOC 2 page shows exactly where the engagement stands. A standing request is fulfilled when the report is issued; the control record is reviewable today.
An account action, the request files under your Naxis account, and the answer arrives on its thread.
How a deployment is built: the single-tenant boundary, the permission model, the audit chain and the AI data flow: the document a security review starts with.
An account action, the request files under your Naxis account, and the answer arrives on its thread.
Send your own questionnaire: CAIQ, SIG, or your in-house sheet, in the request note. Answers come from the architecture, not a boilerplate script.
An account action, the request files under your Naxis account, and the answer arrives on its thread.
SOC 2 status, answered
Do you have a SOC 2 report?
Not yet, and we say so plainly: the SOC 2 Type II engagement is in preparation and no report is claimed until one is issued. A standing request from your account means the report reaches you the day it exists.
Why does a Type II report take so long?
Because that is what makes it worth reading. A Type I describes controls at a point in time; a Type II has an auditor examine evidence across a live observation window of months. The window cannot be compressed, evidence has to accrue.
What can our security team review before the report exists?
The same controls the audit will examine: the security & architecture overview, the trust library, the hash-chained audit log design, the release gate, and your own questionnaire answered from the architecture. All requestable from your account today.
Which Trust Services Criteria will be in scope?
Security as the required baseline, with Availability, Confidentiality and Processing integrity mapped below, the final scope is stated with the engagement, and this page will say exactly what the report covers, no more.
Can we buy before the report exists?
Yes, organisations that must answer for their data do it by assessing the mechanisms directly and contracting the DPA. The report, when issued, confirms what you already reviewed; a standing request keeps you first in line.
Assess the controls yourself.
The report, when it comes, will confirm what you can already review, not reveal it.