Handing over your data to a vendor isn’t something to take lightly. When sensitive information is on the line, some spiel on a website about “top-tier security” isn’t going to cut it. You need clear, verified evidence that your data is safe and sound.
With that said, Filestage recently got its SOC 2 report with zero findings, backed by six months of continuous, real-world evidence. Every control the team shared with the auditors held up, every time it was checked. (Can you tell we’re proud?)
We thought this would be a great time to sit down with Prince, our Information Security Manager at Filestage, to discuss what it takes to earn those SOC 2 stripes and the learnings he picked up along the way.
If at this point you’re wondering “… What is SOC 2?” we’ve got you. Let’s answer that first.
What is SOC 2?

SOC 2 is an audit standard developed by the American Institute of CPAs (AICPA). It evaluates how effectively a company protects its customers’ data. Auditors leave no stone unturned, inspecting confidentiality, availability, and privacy to verify whether a company’s safeguards work in practice, not just on paper.
SOC 2 has two different Types:
- Type 1 acts like a snapshot. It confirms whether your security controls are properly designed at a single point in time.
- Type 2 checks whether those controls held up over months of continuous use. In Filestage’s case, auditors reviewed six months of active operational evidence.
“You’re only as strong as the weakest link in your chain.”
Enterprise clients and teams, especially in regulated industries, work with some hefty auditing obligations. Their procurement and security departments need absolute proof that every vendor touching their data handles it with the same level of care they do themselves.
As Prince put it,
“There may be data that should not be open for public release… maybe if it’s leaked it would cause damage to a campaign that hasn’t yet launched, maybe it would cause irreparable harm to a customer relationship.”
This is where SOC 2 shines.
Instead of a security team writing out a 300-question questionnaire before every deal, they can ask for the report and check it against what they’d expect from a supplier at that level. So it shortens procurement, but that’s just a little perk.
The real question enterprises need to ask is whether they can be sure the data they share will be protected and not end up in the wrong hands.
SOC 2 gives you your answer, or a big part of it at least.
Prince was crystal clear about what SOC 2 can and can’t do:
“It doesn’t guarantee that an advanced threat isn’t going to do some harm if given the chance. It’s essentially just a way to say, we’re doing everything we can to safeguard your data.”
What it took to get certified
Prince has an auditing background, so it wasn’t easy to surprise him when it comes to the auditing process itself. But he did emphasize just how much cross-functional team effort sits behind one clean report.

Sure, the Security team writes the policies, designs controls, and runs risk assessments. But the actual evidence comes from across the entire company:
- HR enforces background screenings during hiring and writes confidentiality clauses into employment contracts
- Engineering integrates automated security scanning into continuous delivery pipelines so unverified code never reaches production
- The wider team completes security training on schedule, updates devices on time, and requests approval before signing up for new software
Passing a Type 2 audit essentially proves that people follow these security habits consistently.
Two key takeaways from the audit
We asked Prince if he could share any learnings with us, looking back on the whole process. He had two clear takeaways.
1. Words matter as much as actions
As an example, we enforce mandatory screen locks and remote access safeguards on all personal devices. But because our rules lived inside a document titled “Remote Access Policy” rather than “Bring Your Own Device (BYOD),” the auditors asked for explicit clarification.
It was a sharp reminder that a Type 2 audit checks not only whether you do the right things, but if your documentation aligns with standard industry wording.
2. “Shadow AI” is the new phishing
Most of us already know how to spot a suspicious email by now. But fewer stop to think about the everyday web tools we test out on our own.
Prince gave us an (all too real) example.
“You can quickly sign up to ChatGPT or you can sign up to Claude and you can ask it a few things, make it do a few things, and you’re just giving away information.”
Testing unvetted AI tools without running them past security or legal first is one of the easiest ways to accidentally leak data. Prince’s rule of thumb for teams is to always ask first.
Security isn’t a one-time badge
SOC 2 compliance is an ongoing process. Our current report covers the six months through to June 2026, and the next audit is already booked for six months out, followed by another twelve-month check. Paired with our ISO 27001 recertification cycle, Filestage is constantly evaluated against real operational proof.
Paperwork isn’t the only thing being checked either. It’s our entire way of working. We also bring in outside help to test the platform itself. As Prince explained,
“Every year we bring in ethical hackers. They come in, they try to hack into the Filestage platform, the staging environment, not the production”
Want to see our shiny new SOC 2 Certificate of Completion? You’ll find it in our Trust Center, alongside our other security and compliance documents.
