SOC 2 Compliance Documentation
Where TokenGrill stands on SOC 2, which controls are implemented today, and what a reviewer can ask for right now.
Status: controls are designed and operating against the SOC 2 Trust Services Criteria (Security, Confidentiality, Availability). An independent Type II attestation has not been completed. We will not describe ourselves as SOC 2 certified until a report exists.
Controls implemented today
- Row-level security isolating every firm workspace, enforced in the database.
- Append-only audit logging of privileged actions, with update and delete revoked.
- Invite-only access provisioning with per-firm roles.
- Secrets held in managed secret storage; no provider keys in client code or source control.
- Encryption in transit for all traffic and at rest for all stored metadata.
- Least-privilege service roles for backend execution paths.
What we can share now
- The security whitepaper and network/data-flow description.
- A control matrix mapping our implemented controls to the Trust Services Criteria.
- Our sub-processor list and change-notification commitment.
- Answers to your own vendor security questionnaire (CAIQ, SIG-lite, or bespoke).
Roadmap
Type II observation requires a continuous window of evidence. Firms that need a completed report before rollout typically start with a limited pilot under the DPA while the observation window runs. We will tell you exactly where we are in that process rather than giving a date we cannot hold.
Need this in writing for your review?
We share the underlying documentation with security and risk teams under NDA, and will walk your counsel through anything on this page.
Request documentation