Skip to content
← Glossary

Entropy scoring & verification

SOC 2 (Type I / Type II)

An independent auditor’s report on a company’s security controls. Type II covers controls operating effectively over a period of months, not just a single point in time — a stronger signal than Type I. Entropy accepts a current SOC 2 report as evidence toward a vendor’s Governance score.

More: Why an early-stage vendor may not have SOC 2 yet