Compliance & legal

    Does Your Security Guard Software Need to Be SOC 2 Certified?

    Why clients ask about SOC 2 security guard software, what SOC 2 covers, and the right vendor security questions to ask. Get the honest checklist.

    Yonah Nathan

    Yonah NathanCo-founder & Head of Product

    Published July 12, 2026 Updated July 23, 2026 5 min read
    Executive summary

    Enterprise clients ask about SOC 2 because your guard software holds their site data — post orders, incident reports, visitor logs. SOC 2 is an independent audit of a vendor's security controls, and the honest state of the guard-software industry is that many tools, especially newer ones, don't have it yet. What matters today is asking the right substitute questions: encryption, access controls, backups, data ownership, and export rights.

    I sit on both sides of this question. As an operator running 400+ guards across Houston, Corpus Christi, Las Vegas, and Florida, I fill out vendor security questionnaires from corporate clients. As the founder of SNTNL, I answer them about our own platform. Here's the straight version of what SOC 2 means for guard companies — including where we stand.

    Why do corporate clients ask about SOC 2 and vendor security?

    Because your software is their risk. When you guard a Fortune 500 distribution center or a Class A office tower, your platform holds their post orders, access procedures, incident reports, and visitor data. Their procurement and infosec teams are required — often by their own auditors and cyber-insurance carriers — to assess every vendor in that chain. Guard companies increasingly count as data vendors, not just labor vendors.

    So the questionnaire lands on your desk: "Is your workforce management software SOC 2 certified? Describe encryption at rest. Describe your backup and recovery procedures." If you can't answer, you look like the risk. Commonly, these reviews now gate RFPs at larger accounts — the contract math is brutal when a $25–35/hr bill-rate account worth six figures a year stalls over a security questionnaire.

    What does SOC 2 actually cover, in plain English?

    SOC 2 is an attestation framework from the AICPA (the American Institute of Certified Public Accountants). An independent CPA firm audits a software vendor against the Trust Services Criteria — security is mandatory; availability, processing integrity, confidentiality, and privacy are optional add-ons. Two flavors:

    • Type I: a snapshot — were the controls designed properly on a given day?
    • Type II: the stronger one — did the controls actually operate over a period, commonly 3–12 months?

    The output is a detailed report (shared under NDA), not a badge. Important nuance: SOC 2 doesn't certify that software is "unhackable." It attests that the vendor has defined security controls — access management, change management, monitoring, incident response — and, for Type II, that they followed them. It's proof of discipline, not invincibility.

    What's the honest state of SOC 2 in guard-industry software?

    Mixed, and often opaque. Some large platforms in the space — TrackTik, for example, positioned at the enterprise tier — advertise formal security programs, while many smaller and newer guard-tour tools publish little or nothing about independent audits. A Type II audit commonly costs tens of thousands of dollars and takes the better part of a year including the observation window, which is why young vendors of every size sequence it after product maturity. If a sales rep waves vaguely at "bank-level security," ask to see the actual SOC 2 report under NDA. If there isn't one, that's not automatically disqualifying — but it means you should ask sharper substitute questions:

    1. Encryption — is data encrypted in transit (TLS) and at rest?
    2. Access controls — per-user logins, role-based permissions, and audit logs? (Shared logins are how client data leaks and how evidence loses its chain of custody.)
    3. Backups and recovery — how often, stored where, and when was restore last tested?
    4. Data ownership — does the contract say your data is yours?
    5. Export rights — can you get everything out, free, at any time? Per user reviews on Capterra and Trustpilot as of mid-2026, exit friction — from 12-month minimum contracts to billing disputes after cancellation — is a recurring complaint in this category, and data lock-in is the sharpest form of exit friction.
    6. Infrastructure — is it built on audited enterprise cloud providers, or a rack nobody talks about?

    Where does SNTNL stand on SOC 2?

    Honestly: SNTNL is not SOC 2 certified today. I won't imply otherwise, and I'd encourage you to distrust any young vendor who fudges this.

    Here's what is true. SNTNL runs on enterprise cloud infrastructure — Supabase (managed Postgres) for the database layer and Cloudflare for the edge and network layer — providers whose underlying platforms maintain their own independent security audits and certifications. Data is encrypted in transit and at rest. Access is per-user with role-based permissions and unlimited users, so nobody shares logins to save money. Client portals are scoped so each client sees only their own sites. Report delivery is logged. And free data export always is a standing commitment, not a negotiation — the platform has run Ranger Guard's live operations for over a year, with 150+ GB of operational data under exactly these controls. Formal SOC 2 certification is on our roadmap as the company matures; until it's done, we'd rather show you the architecture than sell you a badge we don't have.

    What should be on your vendor security cheat-sheet?

    Steal this table for your next software evaluation or client questionnaire:

    Question to askGood answer looks likeRed flag
    SOC 2 report available?Type II report under NDA, or an honest "not yet, here's our roadmap"Vague "enterprise-grade security" claims
    Encryption in transit/at rest?TLS everywhere; encrypted storage"Our data center is secure"
    Access model?Per-user logins, roles, audit logsPer-user pricing that incentivizes shared logins
    Backups?Automated, off-site, tested restores"We've never needed one"
    Who owns the data?You do, in writingSilence in the contract
    Export rights?Full export, free, anytimeExport fees or "talk to support"
    Infrastructure?Named, audited cloud providersUnnamed or self-hosted mystery

    The same logic applies when you're the vendor: answering a client's questionnaire well is part of the same discipline as proving your patrols happened — evidence over assertion.


    If you're staring down a client security questionnaire, book a demo — I'll walk you through how SNTNL is built, what we can answer today, and exactly where we are on the certification roadmap. No badge-waving, just the architecture.

    Keep reading

    Book a demo