Docmosis Successfully Completes SOC 2 Type II Audit

24 December 2025

We’re pleased to share that Docmosis has successfully completed a SOC 2 Type II examination and received the report for Docmosis Cloud, our document generation service.

Our earlier SOC 2 Type I report focused on whether the controls were designed appropriately at a point in time. SOC 2 Type II looks at how those controls operate over a defined audit period as part of normal business operations, while the Cloud service is being actively used by customers.

What the SOC 2 Type II report covers

The SOC 2 Type 2 assessment focused on controls that have been in place for many years. Automated compliance tooling is used to collect evidence and monitor key controls during the audit period. External specialists assist in reviewing this evidence and recommending refinements where needed.The report confirms that:

  • Controls were assessed over a clearly defined audit period
  • The auditor tested whether those controls operated consistently during that period.
  • The controls evaluated are the ones used to run the live service.
  • Both documented design and observed operation were considered

Why this matters for customers

Most teams don’t just need assurance that good security practices exist on paper. They need confidence that they’re consistently applied.

For customers using Docmosis Cloud in production workflows, this assessment provides independent assurance that the security controls supporting the service are in place and are operating as intended over time. That can be especially helpful for:

  • Vendor risk reviews and due diligence
  • Internal security questionnaires
  • Procurement processes that ask for third-party assurance
  • Ongoing compliance obligations where evidence needs to be retained

How we maintain controls over time

The controls assessed in the Type II report form part of an established security-focused framework that was already in place before the audit period began. To support consistency and traceability, we use automated compliance tooling to collect evidence and track selected controls. We also work with external specialists who help review findings and recommend improvements where appropriate.

Importantly, this work happens alongside normal Docmosis operations. There is no “audit mode,” and no planned downtime. It’s business as usual and customers continue to use the API while evidence is gathered and reviewed.

Accessing the SOC 2 Type 2 report

The SOC 2 Type II report for Docmosis Cloud is available to customers through the Docmosis Trust Portal.

Security, risk, and procurement teams can request the report when they need detailed assurance and retain it as part of their own review and compliance records.

A note of thanks

Completing a SOC 2 Type II assessment was an important milestone for Docmosis and one we committed to achieving in 2025. We’re proud of the work the team put in to reach this point, and we’re treating it as a step forward rather than a finish line. Our focus now is on continuing to mature the program, strengthening consistency, and extending independent assurance further over time as part of our 2026 roadmap.