Where to get your vendors’ SOC 2 reports

Your SOC 2 auditor will ask how you reviewed the vendors that touch customer data, and the usual answer is each vendor’s own SOC 2 report. Most vendors keep it behind a trust center, a dashboard page or a request form. This page lists where 30 common startup vendors publish theirs and who is allowed to download it, then explains what to check once you have the PDF.

Each entry was checked against the vendor’s own pages on September 28, 2026. Access terms change; confirm on the vendor’s page before you rely on one.

Vendor SOC 2 reports by vendor

Cloud

VendorHow to get the report
AWSDownload SOC reports in AWS Artifact from the console at no charge; the AWS SOC FAQ says an NDA acceptance applies.
Google CloudType II statedDownload through Compliance Reports Manager at no extra cost after signing in with a Google Cloud account; confidentiality terms of your agreement apply.
Microsoft AzureType II statedDownload from the Microsoft Service Trust Portal SOC reports section; Azure DevOps reports can be requested by email.

Hosting

VendorHow to get the report
VercelType II statedRequest access through the Vercel Trust Center, where the current SOC 2 Type 2 report can be downloaded once access is granted.
CloudflareType II statedSuper Administrators download it from Compliance Documents in the dashboard after agreeing to a confidentiality statement; an NDA is required.
HerokuLog a compliance document request ticket with Heroku Support to receive the SOC 2 report.
NetlifyType II statedAny Netlify account can open the Trust Center and request the SOC 2 Type 2 report; Enterprise accounts with an NDA are approved automatically.

Database

VendorHow to get the report
SupabaseType II statedTeam and Enterprise plan customers download it from the Legal Documents section of the organization dashboard.
MongoDB AtlasType II statedExisting customers request it from the Customer Trust Portal; prospects contact MongoDB; an NDA or customer status is required.
SnowflakeType II statedCustomers self-request and download it from Snowflake's Compliance Center (trust center).

Code

VendorHow to get the report
GitHubType II statedEnterprise Cloud owners download it from the Compliance tab in enterprise settings.
GitLabType II statedDownload from the GitLab Trust Center; the security page confirms a SOC 2 Type 2 report for GitLab.com and Dedicated.

Identity

VendorHow to get the report
OktaRequest access via the Okta Security Trust Center, which lists the SOC 2 report; a security review may be required.
1PasswordType II statedSubmit contact details on the 1Password SOC page and the SOC 2 Type 2 report is emailed to you.
Auth0Auth0 reports are in Okta's Security Trust Center; complete the security review and request access.

Observability

VendorHow to get the report
DatadogType II statedRequest access through the Datadog Trust Center, which lists SOC 2 Type 2 under compliance.
SentryType II statedExisting Sentry users access the SOC 2 Type 2 report via their account; others contact Sentry's enterprise team.
PagerDutyType II statedRequest the SOC 2 Type II report through PagerDuty's assurance portal.

AI

VendorHow to get the report
OpenAI (API)Type II statedCustomers with an account on the OpenAI Trust Portal access it under Compliance; the report covers the API Platform.
AnthropicType II statedAnthropic's privacy center says to request compliance documents, including SOC 2 Type II, through its Trust Portal.

Payments

VendorHow to get the report
StripeType II statedStripe says SOC 1 and SOC 2 Type II reports are produced annually and provided on request.

Collaboration

VendorHow to get the report
SlackType II statedSubmit Slack's Privacy and Security request form to receive the SOC 2 Type II report.
Google WorkspaceType II statedDownload through Compliance Reports Manager at no extra cost, signing in with a Google Workspace account.
Microsoft 365Type II statedSign in to the Service Trust Portal with an existing Office 365 subscription or free trial to download SOC 2 reports.
Atlassian (Jira/Confluence)Type II statedDownload from the Compliance Resource Center after accepting an NDA and entering your email.
NotionType II statedSubmit an access request through the Notion Trust Center; Notion lists SOC 2 Type II among its audits.
LinearType II statedLinear states it undergoes SOC 2 Type II audits and directs report requests to its trust center.

Communications

VendorHow to get the report
TwilioRequest security and privacy documents, including the SOC 2 report, through Twilio's security documentation portal.
ZoomType II statedRequest through the Zoom Trust Center with a corporate email; the SOC 2 Type 2 report and bridge letter are offered.

CRM

VendorHow to get the report
HubSpotType II statedCustomers confirm their email for full trust center access; non-customers complete a clickwrap NDA to see the SOC 2 Type II report.

What to check in a vendor’s SOC 2 report

Downloading the report is not the review. Read these parts and write down what you found:

  1. Type and period. A Type II report covers a period of operation; a Type I is a single date. Note the period end. If it ended long ago, ask for the newer report or a bridge letter.
  2. Scope. Check that the system description covers the product you actually use. Large vendors publish several reports; the one for another product line does not help you.
  3. The auditor’s opinion. An unqualified opinion is the expected result. A qualified opinion means the auditor found a material problem; read which criterion and why.
  4. Exceptions in the test results. Even with a clean opinion, individual tests can show deviations. Decide whether any of them affect how you use the vendor.
  5. Complementary user entity controls. This section lists what the vendor expects you to do, such as enabling MFA, managing your own users or configuring encryption. Those become your controls; check that your policies cover them.
  6. Subservice organizations. The vendor’s own vendors (often a cloud provider) are listed here, usually carved out. Note them in your vendor inventory as fourth parties.

Record the review with the date, the report period, the reviewer, any exceptions and the decision. That record, not the PDF, is the evidence your auditor samples. The Vendor and Third-Party Risk Management Policy template sets out the inventory, the risk tiers and the review cadence, and you can download it as Word in your company’s name from that page.

Keep it proportionate

A small company can easily use dozens of SaaS tools, and not all of them need a SOC 2 review. Tier vendors by the data they touch: the ones that store or process customer data (cloud, database, hosting, email, support tools) get a full review with the report; tools with no customer data get a short documented check. The auditor looks for a consistent rule applied to the whole inventory, not for a PDF from every tool.

Frequently asked questions

Why do I need my vendors' SOC 2 reports?
SOC 2 criterion CC9.2 expects you to assess and monitor the risk from vendors and business partners. For any vendor that stores or processes customer data, a current SOC 2 Type II report is the standard evidence that you did. Your auditor will ask for the vendor inventory and for the reviews of the vendors on it.
What if a vendor has no SOC 2 report?
Ask for an equivalent: an ISO/IEC 27001 certificate with its statement of applicability, a completed security questionnaire, or a penetration test summary. Record which one you received, the risk you accepted and who approved it. For a low-risk vendor that never touches customer data, a short documented review is normally enough.
What is a bridge letter?
A SOC 2 Type II report covers a fixed period that ended some months before you read it. A bridge (or gap) letter is the vendor management's statement that nothing material changed between the end of that period and a later date. Ask for one when the report period ended more than a few months ago.
Do I need to review every vendor every year?
Review vendors on the schedule your vendor policy sets, tiered by risk. Vendors that hold customer data are usually reviewed annually with a fresh SOC 2 report; low-risk tools can be reviewed less often. The auditor tests that you did what the policy says, so set a cadence you will keep.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.