Security

BeeSign Achieves SOC 2 Type 1: Our Security Controls, Independently Audited

An independent CPA firm examined how BeeSign protects your documents against the AICPA Trust Services Criteria for Security — and issued an unmodified opinion. Here's exactly what was audited, what a SOC 2 Type 1 report does and doesn't prove, and how to get a copy.

MA

Mustafa Abusharkh

August 14, 2026
6 min read
BeeSign Achieves SOC 2 Type 1: Our Security Controls, Independently Audited

Every e-signature platform on the market tells you it's secure. We've said it too — on our security page, in sales calls, in answers to vendor questionnaires. The problem with saying it is that anyone can. So we brought in an independent licensed CPA firm to check. BeeSign has completed a SOC 2 Type 1 examination of its Electronic Signature Platform, and the auditor issued an unmodified opinion.

Here's what that actually means, what was examined, and — just as importantly — what a Type 1 report does not prove.

AICPA SOC 2 for Service Organizations seal

SOC 2 Type 1 · Trust Services Criteria for Security

Examined as of August 12, 2026 by Zero Day CPA, PC (Troy, Michigan). Report issued August 13, 2026. No system incidents reported.

What SOC 2 Actually Is

SOC 2 is an examination standard from the American Institute of Certified Public Accountants (AICPA). A licensed CPA firm — the same kind of firm that audits financial statements — examines how a company designs and operates the controls protecting customer data, measured against a published set of criteria called the Trust Services Criteria.

The key word is independent. A SOC 2 report isn't a questionnaire we filled out about ourselves, and it isn't a badge you can buy. It's an outside professional's opinion, backed by their license, after they've asked for evidence and we've had to produce it.

One piece of pedantry worth getting right, because plenty of companies get it wrong: nobody is "SOC 2 certified." There's no certifying body and no certificate. SOC 2 is an attestation — an auditor's opinion in a report. When you see a vendor claim certification, it's a small sign they haven't read their own report.

Type 1 vs. Type 2: Being Straight With You

SOC 2 reports come in two flavors, and the difference matters:

  • 1Type 1 asks: are the controls suitably designed as of a specific date? It's a point-in-time snapshot of the design.
  • 2Type 2 asks the same question and then goes further: did those controls actually operate effectively over a period of months? It requires sampling and testing across time.

BeeSign holds a Type 1 report. The auditor examined the design of our controls as of August 12, 2026 and confirmed they were suitably designed to meet our security commitments. They explicitly did not test operating effectiveness over a period — that's what a Type 2 covers, and we'd rather tell you that plainly than let a badge imply more than it says.

What Was Examined

The scope was the BeeSign Electronic Signature Platform — the system that stores, routes, signs, and seals your documents — against the criteria relevant to Security, the Common Criteria in the AICPA's TSP section 100. Every applicable criterion was relevant to the system; none were carved out as not applicable.

In practice, that meant the auditor looked at areas like these:

  • Logical access. Least privilege, unique IDs with no shared accounts, a second authentication factor on every in-scope system, quarterly access reviews, and removal of access within 24 hours of someone leaving.
  • Change management. All code in version control, tested outside production, and unable to reach the production branch without at least one independent approval.
  • Encryption. TLS 1.2/1.3 in transit and AES-256 at rest for documents, metadata, and signature profiles.
  • Vulnerability management. Continuous dependency and image scanning, with critical and high findings remediated on a risk-based schedule, plus an annual network configuration review.
  • Monitoring and incident response. Logging and alerting that route events to the right people, a written incident response plan, and an annual tabletop exercise to rehearse it.
  • People and governance. A Security Steering Committee that meets quarterly, background checks where local law permits, and security awareness training on hire and every year after.
  • Risk and vendor management. A formal annual risk assessment against a maintained risk register, and annual review of compliance reports for high-risk vendors.

Behind those controls sit fifteen written policies — information security, access control, encryption and key management, secure development, incident response, business continuity, and more — each reviewed and approved at least annually.

What About Google Cloud?

BeeSign runs entirely on Google Cloud Platform and operates no data centers of its own. In SOC 2 terms, Google is a carved-out subservice organization: the examination covered BeeSign's controls plus the complementary controls we assume Google provides, while Google's own controls are attested separately in its SOC 1 and SOC 2 Type II reports.

That's the standard and honest way to handle it. Physical data center access, power, and environmental safeguards aren't ours to control, so we don't claim credit for them — we rely on Google's attestations and review them.

What This Means If You're Evaluating BeeSign

If you've ever had to push an e-signature vendor through procurement, you know the drill: a security questionnaire, a back-and-forth about encryption, and someone in IT asking whether anyone outside the company has ever verified any of it. A SOC 2 report is the artifact that ends that conversation early.

  • Vendor reviews move faster. Hand your security team the report instead of a marketing page.
  • You can see our homework. The report includes the full control matrix mapped to criteria CC1 through CC9 — not a summary, the actual controls.
  • You'll know your own obligations. It lists the complementary user entity controls — the things your side has to do, like managing your users' access and telling us promptly about a suspected compromise.

It also sits alongside the rest of what we've built: signatures that are legally binding under ESIGN and UETA, eIDAS Advanced Electronic Signatures, HIPAA-aligned safeguards, an A+ Qualys SSL Labs rating, and blockchain timestamp proof on every completed document.

How to Get the Report

We're not publishing it as a public download, and no reputable vendor should. SOC 2 reports are restricted-use documents — the AICPA limits distribution to customers, prospective customers, business partners, their practitioners, and regulators with enough understanding of the system to interpret it properly.

So: ask us. If you're a customer or evaluating BeeSign, get in touch, mention the SOC 2 report, and we'll share the full document under an NDA. Details are on our SOC 2 page.

Why We Did This

BeeSign is a small, security-first company competing against names everyone recognizes. We can't ask anyone to take security on faith just because we say we care about it. An audit is how a smaller team proves the same things a big one does — with the same standard, the same criteria, and the same independent scrutiny.

Your contracts, patient forms, and employment agreements are some of the most sensitive documents your business handles. You should expect the platform holding them to show its work. Now ours is on paper — read what the audit covered, or start your free trial and put it to use.

Ready to transform your workflow?

Start using BeeSign today and experience the future of document signing

Related Articles

Blockchain Timestamping with OpenTimestamps: How BeeSign Proves When a Document Was Signed
Security

Blockchain Timestamping with OpenTimestamps: How BeeSign Proves When a Document Was Signed

Every completed BeeSign document is anchored to the Bitcoin blockchain with OpenTimestamps — an independent, tamper-proof record of exactly when it was signed that anyone can verify, with no trust in BeeSign required. Here's how it works and why it matters.

MA

Mustafa Abusharkh

7 min read