What SOC 2 is and why it is important both start with one fact: it is a report, not a certificate. A licensed CPA firm examines a software company's controls over security (always), and optionally availability, processing integrity, confidentiality and privacy, and writes an opinion. Type 1 describes the controls on one day; Type 2 tests whether they worked over a period, usually three to twelve months. It is voluntary and says nothing about whether the software gives correct answers. For an owner choosing a finance app, ask for a Type 2 report, its date, its scope, and whether the vendor will show it. Then read the exceptions, not the cover.
Why SOC 2 is important now
Since 28 July 2026, ChatGPT and Claude can connect straight to QuickBooks Online, and Intuit's own list of what they can do includes creating and deleting invoices. Meanwhile the number of apps a bookkeeper has quietly attached to each file has kept growing.
The Verizon 2026 Data Breach Investigations Report, released 19 May 2026, gives the wider picture: breaches involving a third party now account for 48 percent of all breaches, third-party supply chain breaches rose 60 percent, 31 percent of breaches start with a software vulnerability being exploited, and the share of employees using unapproved AI tools went from 15 to 45 percent in a single year. Intuit's 2026 AI Impact Report found privacy and security is the top barrier to owners adopting AI, ahead of the fear of errors, and BILL's 2025 survey of 750 owners named information security and incorrect information as the two main drawbacks. The worry is reasonable. The phrase most vendors answer it with is "SOC 2", and most owners nod without knowing what it covers.
What the report is
SOC 2 is an examination under which an independent CPA firm tests a service company's controls against the AICPA's Trust Services Criteria and issues a report with an opinion. A-LIGN's 2026 guide calls it "an independent attestation that evaluates the effectiveness of a company's controls as they relate to Security, Availability, Processing Integrity, Confidentiality, and Privacy", and notes that only licensed CPA firms accredited by the AICPA can perform one.
The Trust Services Criteria are the five categories a SOC 2 can cover. Security is always in scope. The other four are optional, and a vendor chooses which to include, so two reports with the same name can test very different things.
A Type 1 report describes the controls and says they were suitably designed on a single date. A Type 2 report tests whether the controls actually operated over a period, which A-LIGN puts at usually between three and twelve months, and records each test that failed.
An attestation is an auditor's written opinion about someone else's claims. A certification is a pass or fail against a standard, issued by a certifying body. SOC 2 is the first, which is why "SOC 2 certified" is a phrase to be wary of; the honest form is "we hold a SOC 2 Type 2 report".
A bridge letter is a short letter from the vendor stating that nothing material has changed between the end of the last report period and today. It is what you ask for when the report you are handed is more than a few months old.
Reading one in fifteen minutes
A SOC 2 report runs to dozens of pages and most of it is boilerplate. The auditor's opinion should be unqualified. The system description names the product, the data centers or cloud regions, and the subprocessors, meaning the other companies that touch your data. After that come the criteria in scope, the tests the auditor ran, and the exceptions, which are the tests that failed and what the vendor said about them. Read the exceptions first; a report with none is either a very well-run company or a very narrow scope.
Suppose the report lands in your inbox on 17 September 2026. The cover says Type 2, the auditor is a named CPA firm, the opinion is unqualified, and the period is 1 March 2025 to 31 August 2025. That period ended twelve and a half months ago, so the first question is where the next report is and whether the vendor will provide a bridge letter for the gap. The exceptions section lists two: quarterly access reviews ran late in two of two quarters, and a contractor who left kept system access for eleven days. Neither is disqualifying. Both tell you what to ask about, and the vendor's written response to each tells you more about the company than the opinion does.
What it does not cover
A SOC 2 report says nothing about whether the numbers the app shows you are right. It does not test whether an AI feature answers correctly, and AI mistakes that look right are a different kind of risk from a data breach. It does not tell you what the app is allowed to do inside your books. Since Intuit's connector release in July 2026, a connected app can inherit the connecting user's role and, in the case of the ChatGPT and Claude connectors, create, send and delete invoices, as described in the read-only question for those connectors. A vendor can hold a clean Type 2 and still have write access it does not need.
Most advice on this says no report, no deal. We would put it differently. A three-person vendor with a recent Type 1, a named auditor and a date, a summary of a penetration test, and a read-only connection is a better risk than a large vendor with a two-year-old Type 2 and write access to every file.
What a report costs, and what to accept instead
A-LIGN puts the cost of a SOC 2 at $20,000 to $150,000 or more, with a Type 1 taking two to four weeks to obtain and a Type 2 six to twelve months. That is why a young vendor may not have one yet, and it is not by itself a reason to walk away. Ask what exists instead. What you can accept in the meantime is a Type 1 dated within the year, the name of the CPA firm engaged for the Type 2 and the period it will cover, a penetration test summary from a named firm, and plain written answers about where your data is stored and who can see it. What you should not accept is the phrase "SOC 2 compliant" with nothing behind it.
Does QuickBooks have one
Intuit's compliance page lists PCI DSS, SOC reports, ISO 27001 and a VPAT, describes SOC reports as providing "assurance over a service organization's internal controls", and routes requests through a compliance portal; its ISO 27001 certifications run three years with annual surveillance audits. So the report exists. Obtaining it as a small customer is the hard part. A QuickBooks Community thread titled "I need the Quickbooks online SOC 2 report" sits alongside another asking "What does it take to get a SOC2 report from QuickBooks? One week, four phone calls/chats and still nothing", and a third asking where to download one. If a bank or insurer needs it, use the portal, put the request in writing, and expect a non-disclosure agreement first.
For the AI tools people connect to those files, OpenAI's enterprise privacy page lists SOC 2 Type 2 for its Enterprise, Business and API products, and Anthropic states that its commercial products do not train on customer content by default. Whether it is safe to upload financial statements to ChatGPT or Claude covers which tiers those statements apply to.
Six questions before you connect anything
Ask whether the report is Type 1 or Type 2. Ask for its date and the period it covers. Ask which product and which criteria are in scope, because a report on the vendor's marketing website is not a report on the app holding your ledger. Ask which subprocessors hold your data and in which country. Ask whether the connection to QuickBooks Online reads your file or can write to it, and get the answer from the connection screen, not the sales deck. And ask what happens to your data after you disconnect, because Intuit's own help page warns that data may be separately maintained by apps after disconnecting. Checking which apps are connected to your files, and disconnecting them is the companion job.
Navigator's connection to QuickBooks Online is read-only, which is the control on that list that matters most, since nothing the app does can change an entry in your books. What Navigator stores, where it is held, and what it does and does not hold by way of a SOC 2 report are stated on the site at navigatorhq.ai, and we keep that current there rather than repeating it here where it would age.
The multi-file point is the one owners miss. One app connected to five company files is one report to read, once. One bookkeeper's tool you never vetted, connected to five files under her login, is five exposures with no report at all. The Verizon figure on third parties is not about the vendors you chose carefully. It is about the ones nobody chose.
Reading a SOC 2 tells you how a vendor behaved during a past period, as observed by an auditor the vendor paid. It is the best evidence available to a buyer who cannot inspect the vendor's systems, and it is still evidence rather than proof.
Questions owners ask
What is the difference between SOC 2 Type 1 and Type 2?
A Type 1 report describes a company's controls and says they were suitably designed on one date. A Type 2 report tests whether those controls operated as described over a period, usually between three and twelve months according to A-LIGN's 2026 guide, and lists every test that failed. Type 1 takes a few weeks to obtain; Type 2 takes six to twelve months. Type 2 is the one worth asking for.
Is SOC 2 mandatory?
No. No law requires a software company to have one. It is a voluntary examination that vendors commission because customers, banks and insurers ask for it, and only a licensed CPA firm accredited by the AICPA can perform it. A vendor without one has not broken any rule. It has just not paid for an outsider to test its controls, and you should ask what it can show instead.
Does SOC 2 mean my data is safe?
It means an independent CPA firm tested the vendor's security controls and wrote down what it found, including the failures. It does not mean nothing can go wrong, and it says nothing about whether the app's numbers are right, whether its AI makes mistakes, or what it does with write access to your books. Read it as evidence that someone checked, and then read the exceptions.
Does QuickBooks have a SOC 2 report?
Intuit's compliance page lists SOC reports alongside PCI DSS and ISO 27001 and offers them through a compliance portal. Getting a copy as a small customer is another matter. QuickBooks Community threads describe a week and four support contacts without result. If your bank or insurer needs it, start with the compliance portal, put the request in writing, and expect to sign a non-disclosure agreement.
What should I ask a software vendor about security before I connect it to my books?
Six things. Is the report Type 1 or Type 2. What date does it carry and what period does it cover. Which product and criteria are in scope. Which subprocessors hold your ledger data and where. Does the connection read your QuickBooks file or can it write to it. And what happens to your data after you disconnect. A vendor that answers all six in writing is ahead of most.
Related
If the question is what to paste into an AI tool at all, start with is it safe to upload financial statements to ChatGPT or Claude. For the connectors themselves, read the ChatGPT and Claude QuickBooks connector and the read-only question, and for the apps already attached to your files, how to check and disconnect QuickBooks connected apps.
If you would like to see what a read-only connection looks like from the inside, the trial takes about fifteen minutes, shares no password and needs no card: navigatorhq.ai.
You're on the list.
The next post goes to . While you wait, the free Accounting Health Check scores your own books.
Published . Last updated . Reviewed by a CFO on the Navigator team.