SOC 2 Type 1 · Security

Our security controls, independently examined.

BeeSign completed a SOC 2 Type 1 examination of its Electronic Signature Platform as of August 12, 2026. An independent licensed CPA firm reviewed how we protect customer documents against the AICPA Trust Services Criteria for Security — and issued an unmodified opinion.

AICPA SOC 2 for Service Organizations seal

About the report

Report type
SOC 2 Type 1
Trust services category
Security (Common Criteria)
System examined
BeeSign Electronic Signature Platform
As of date
August 12, 2026
Report issued
August 13, 2026
Independent service auditor
Zero Day CPA, PC — Troy, Michigan
Opinion
Unmodified — controls suitably designed
Reported system incidents
None

A Type 1 report attests to the suitability of the design of controls at a point in time. A Type 2 report additionally tests that those controls operated effectively over a period.

What was examined

The scope was the BeeSign Electronic Signature Platform — the system that stores, routes, signs, and seals your documents — measured against the criteria relevant to Security in TSP section 100, the AICPA Trust Services Criteria. Every applicable criterion was relevant to the system; none were carved out as not applicable.

BeeSign runs entirely on Google Cloud Platform and operates no data centers of its own. Google is treated as a carved-out subservice organization: the examination covered BeeSign's controls plus the complementary controls we assume Google provides, while Google's own controls are attested separately in its SOC 1 and SOC 2 Type II reports.

The auditor reported no system incidents that resulted from unsuitably designed controls or that significantly impaired BeeSign's ability to meet its service commitments.

Logical access

Access to production systems is granted only with a documented business reason and approval, under least privilege. Every user has a unique ID, shared accounts are prohibited, and a second authentication factor is required on every in-scope application. Access is reviewed quarterly and revoked within 24 hours of termination.

Change management

All platform code lives in version control, is tested outside production, and cannot reach the production branch without at least one independent approval. Permission to change those branch protections is restricted to a reviewed set of personnel.

Vulnerability management

Dependencies and container images are scanned continuously with Dependabot and Trivy, and critical and high findings are remediated on a risk-based schedule. Network and firewall configurations get a formal review at least annually.

Encryption and data protection

Customer documents, metadata, and signature profiles are encrypted in transit with TLS 1.2/1.3 and at rest with AES-256. Production infrastructure holding customer data is configured to refuse unauthenticated public access.

Monitoring, logging and alerting

Logs are collected and mined for metrics that surface potential security threats and unusual system activity. Alerting routes events to the responsible people, and every identified event is tracked through to resolution.

Incident response

Confirmed incidents are documented and driven to closure under a written Security Incident Response Plan, with a lessons-learned write-up feeding fixes back into policy. The plan is rehearsed in an annual tabletop exercise.

People and governance

A Security Steering Committee meets quarterly. Personnel acknowledge the Code of Conduct and security policies, pass background checks where local law permits, and complete security awareness training on hire and annually thereafter.

Risk and vendor management

Management runs a formal risk assessment at least annually against a maintained risk register. Vendor agreements carry security requirements, and compliance reports for high-risk vendors are collected and reviewed annually.

The policies behind the controls

Fifteen written policies govern how the platform is built, operated, and defended. Each one is reviewed, updated, and approved at least annually — and whenever the business changes.

  • Information Security Policy
  • Access Control and Termination Policy
  • Acceptable Use Policy
  • Encryption and Key Management Policy
  • Change Management Policy
  • Secure Development Policy
  • Configuration and Asset Management Policy
  • Network Security Policy
  • Vulnerability and Patch Management Policy
  • Risk Assessment and Treatment Policy
  • Vendor Management Policy
  • Security Incident Response Plan
  • Business Continuity and Disaster Recovery Policy
  • Internal Control Policy
  • Code of Conduct

Getting a copy of the report

SOC 2 reports are restricted-use documents. The AICPA limits distribution to customers, prospective customers, business partners, their practitioners, and regulators who understand the system well enough to interpret it — which is why we don't publish ours as a download.

If you're running a vendor security review, ask and we'll share the full report under an NDA. Mention "SOC 2 report" in your message and we'll get it to you.

  • Full independent service auditor's report and opinion
  • Management's assertion and the system description
  • The complete control matrix mapped to CC1 through CC9
  • Complementary user entity controls you're responsible for
  • Complementary subservice organization controls for Google Cloud

Frequently asked questions

What is SOC 2?

SOC 2 is an examination standard from the American Institute of Certified Public Accountants (AICPA). A licensed CPA firm independently examines how a service organization designs and runs the controls that protect customer data, measured against the AICPA Trust Services Criteria. The result is an attestation report — an outside auditor's opinion, not a self-assessment.

What is the difference between a Type 1 and a Type 2 report?

A Type 1 report evaluates whether controls are suitably designed as of a single point in time. A Type 2 report goes further and tests whether those same controls operated effectively across a period of months. BeeSign holds a Type 1 report as of August 12, 2026.

Which Trust Services Criteria does the report cover?

The examination covered the criteria relevant to Security — the Common Criteria (CC1 through CC9) in TSP section 100. Every applicable criterion was relevant to the system; none were excluded. Availability, Processing Integrity, Confidentiality, and Privacy were not in scope for this examination.

Who performed the audit?

Zero Day CPA, PC, an independent licensed CPA firm based in Troy, Michigan. They issued an unmodified opinion: the description presents the Electronic Signature Platform in accordance with the AICPA description criteria, and the controls stated in it were suitably designed to meet BeeSign's service commitments and system requirements.

How do I get a copy of the report?

The report is not published publicly. Use of a SOC 2 report is restricted by the AICPA to user entities, prospective customers, business partners, their practitioners, and regulators who understand the system. If you are a customer or evaluating BeeSign, contact us and we will share the report under an NDA.

Is BeeSign "SOC 2 certified"?

Strictly speaking, no organization is SOC 2 certified — SOC 2 is an attestation, not a certification, and there is no certifying body. What BeeSign has is a SOC 2 Type 1 report from an independent CPA firm containing an unmodified opinion on the design of its security controls.

Does the report cover Google Cloud, where BeeSign runs?

Google Cloud Platform is a carved-out subservice organization. The examination covered BeeSign's own controls and the complementary subservice organization controls assumed in their design; Google's controls are covered by Google's own SOC 1 and SOC 2 Type II reports. BeeSign operates no physical data centers, so data center access, power, and environmental safeguards sit with Google.

What is expected of us as a customer?

The report lists complementary user entity controls — the things that have to happen on your side for the overall system to work. In short: provision, review, and remove your own users' access; make sure only authorized, trained people use BeeSign; supervise how your team uses it; and tell us immediately if you suspect a breach or a compromised account.

This page summarizes BeeSign's SOC 2 Type 1 report for general information. The report itself is the authoritative document and is restricted-use; nothing here is a substitute for reading it. The AICPA SOC 2 seal is a trademark of the American Institute of Certified Public Accountants.

Sign on a platform that passed the audit

Every BeeSign plan runs on the same audited platform — encrypted end to end, with tamper-evident audit trails and a certificate of completion on every document.