August 21, 2026Security

Syyclops Is Now SOC 2 Type II Compliant

Syyclops has completed an independent SOC 2 Type II examination of the Syyclops Digital Twin Platform — third-party validation that our security controls are well designed and operate effectively over time.

ST
Syyclops Team
4 min read

We are excited to announce that Syyclops has achieved SOC 2 Type II compliance. An independent service auditor has examined the Syyclops Digital Twin Platform and issued a SOC 2 Type II report attesting that our security controls were suitably designed and operated effectively throughout the observation period.

For the building owners, facility teams, and IT organizations that trust us with their operational data, this is an important milestone — and one we have been working toward since day one.

What SOC 2 Type II Means

SOC 2 is a reporting framework developed by the American Institute of Certified Public Accountants (AICPA). It evaluates how a service organization protects customer data against the Trust Services Criteria, and it is one of the most widely recognized standards for SaaS vendors serving enterprise customers.

There are two kinds of SOC 2 reports:

  • Type I assesses whether controls are suitably designed at a single point in time.
  • Type II goes further. It tests whether those controls actually operated effectively over an extended observation period.

A Type II report is the more rigorous of the two, because it is not enough to have the right policies on paper — the auditor examines evidence that they were followed consistently, day after day.

One note on terminology: SOC 2 is not a certification. It is an attestation report issued by an independent CPA firm following an examination. That distinction matters, and it is why we say Syyclops is SOC 2 compliant and has an issued SOC 2 Type II report.

Why This Matters for Building Operations

Syyclops connects to the systems that run your buildings: building automation systems, work order and CMMS platforms, BIM models, O&M documentation, and more. That data is operationally sensitive, and your security and IT teams are right to ask hard questions before a vendor connects to it.

A SOC 2 Type II report answers many of those questions up front, with evidence verified by an independent third party rather than a vendor's own claims. In practice, this means:

  • Faster security reviews. Procurement and IT teams can rely on the report instead of lengthy custom questionnaires.
  • Independent validation. Our controls for access management, encryption, change management, vendor oversight, incident response, and monitoring have been tested by an outside auditor.
  • Ongoing accountability. Type II compliance is maintained through continuous monitoring and periodic re-examination, not a one-time check.

Scope of the Examination

ExaminationDetail
SystemSyyclops Digital Twin Platform
Report typeSOC 2 Type II
Observation periodApril 1, 2026 – July 1, 2026
CriteriaAICPA Trust Services Criteria for Security
Independent auditorAdvantage Partners
ResultUnqualified opinion, no exceptions noted

The examination covered the controls we apply across the platform, including the areas described on our Security & Architecture page: encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control and MFA, audit logging, network isolation, secure software development and change management, and vendor and incident management.

Our Partners in the Process

We did not do this alone. We partnered with Advantage Partners, who served as our independent service auditor and guided us through the examination, and Vanta, whose platform we use to continuously monitor our controls and collect evidence. Both were tremendous partners throughout the process, and we are grateful for their support in reaching this milestone.

Compliance Is Continuous

A SOC 2 Type II report reflects a specific observation period, but our commitment to security does not stop when the period ends. We continue to monitor our controls every day through Vanta, and we will undergo regular re-examination to keep our report current.

Security has always been foundational to how we build Syyclops — from our outbound-only gateway architecture and no-training commitment on building data, to the encryption and access controls that protect every customer environment. SOC 2 Type II is independent confirmation of that foundation, and a commitment to keep raising the bar.

How to Request the Report

Current and prospective customers can request our full SOC 2 Type II report, along with other security documentation, through the Syyclops Trust Center. Reports are shared under NDA.

If you have questions about our security program or would like to discuss how Syyclops can fit into your organization's security requirements, reach out to our team — we would be glad to talk.


Learn more about how Syyclops protects your building data on our Security & Architecture page.

Ready to Get Started?

Discover how Syyclops can help transform your infrastructure with digital twin technology and AI-driven insights.