Company News
xop.ai Achieves SOC 1 Type 2 and SOC 2 Type 2
Both examinations are complete, both are Type 2, and the opinion is clean. Why a company this size did them early: we were built by an MSP who spent years on the answering end of these questionnaires, we run least privilege by default, nothing is trained on your data, and we went to real engineering lengths to avoid holding a copy of your clients' documentation at all.
Matt Ruck · September 25, 2026 · 3 min read
That is the whole answer, and it is at the top on purpose. The rest of this is for the person who has to do something with it: what each examination covered, why we ran them this early, and what the reports are actually evidence of.
Why a company this size did them now
Most companies at our stage wait. An audit is expensive, it takes months, and nobody makes you do it until a large deal stalls on it. We did it early because of who built this, and because of a decision we made about your clients' data long before anyone asked us to evidence it.
xop.ai was built by people who ran a $30M MSP for twenty-eight years. That means years on the answering end of exactly this: a client's auditor sends the third-party list, and somebody on your team spends a week assembling evidence about vendors who should have had it ready. We know what it costs an MSP when a supplier cannot produce a report, because we paid that cost.
What the reports are evidence of
An audit does not make a product secure. It tests whether the things you already do are real, and whether you did them consistently across a period. Three of ours are worth naming, because they are design decisions rather than policies.
Least privilege, by default. The agent is granted exactly what it needs in your systems and nothing broader. Our own configuration guides walk an administrator through granting the narrow permission rather than the convenient one, which is the opposite of how most integrations are documented.
Nothing is trained on your data. Zero retention with our model providers, and no training on customer content. Not a setting you have to find and switch off, and not a policy that changes when a provider updates their terms.
We do not try to house your clients' data. This is the one that cost us real engineering time. The ordinary way to build search across documentation is to copy it into a vector database first, which means a second copy of your client's documentation living permanently on our side, with everything that follows from that.
We did not do that. Ask AI runs queries against SharePoint, IT Glue, IT Boost and the rest where the content already lives, in the moment the engineer asks, under the permissions you granted. Building it that way was considerably harder than building a copy would have been. It means the smallest amount of your clients' information sits with us, which is the answer you want when the questionnaire asks what we store.
The reports are evidence of that posture rather than the cause of it. The order matters: we did not design the platform to pass an audit, we ran an audit against how it was already built.
The question you are actually being asked
You are an MSP. One of your clients is going through their own audit, or renewing cyber insurance, or answering a questionnaire from a customer of theirs. Their auditor sends a list of third parties and asks what assurance exists for each one. Somewhere on that list is the AI platform sitting inside your PSA.
You need something to send back. What you can state is that xop.ai holds SOC 1 Type 2 and SOC 2 Type 2 reports with a clean opinion, and what you can forward is the security page, which is written for exactly that and needs no editing first. What you cannot forward is the report itself, and the reason is worth understanding rather than working around.
Type 1 and Type 2 are not the same thing
This is the distinction most people asking for "a SOC 2" have not been told, and it is the one that decides whether the report is worth anything.
- A Type 1 says the controls were designed appropriately, as of a single date. It is a photograph. It says nothing about whether anyone actually followed the controls the day after.
- A Type 2 says the controls were designed appropriately and operated effectively across a period of time, tested by the auditor. It is a recording rather than a photograph.
Both of ours are Type 2. When a vendor tells you they are SOC 2 compliant and does not say which, it is worth asking, because the difference is most of the value.
What the SOC 2 covered
Three of the five Trust Services categories, chosen because they are the three that describe what this platform does with your clients' data:
- Security. The controls protecting the system against unauthorized access, covering the control environment, physical and environmental security, information security, change management and data communications.
- Availability. Whether the system is there when you need it. Backup and storage, system maintenance and uptime.
- Confidentiality. How information designated as confidential is protected through its life, from the point it arrives to the point it is disposed of.
What the SOC 1 covered
SOC 1 is the less familiar one, and MSPs ask why an AI platform has it at all. It covers our administrative controls and back-office operations. The product also touches time entries, and time entries become invoices, so a client's auditor has a legitimate interest in the controls behind it. Having the SOC 1 means that conversation has an answer rather than an argument.
Subservice organizations are carved out
Worth stating because a good auditor will look for it. The examination used the carve-out method, which means the controls of subservice organizations, the infrastructure and model providers underneath us, are excluded from the scope of our report and covered by their own. That is the normal approach and it is not a gap, but it does mean our report is about our controls rather than about everyone's. The providers we use are named on the security page.
Who the report can go to, and why it is narrower than you expect
Every SOC report carries a restricted-use legend, and ours is the standard one. It names three parties: our management, our user entities, and those user entities' own auditors. A user entity is a customer, during the period the report covers.
So if you are a customer, the report is yours, and it goes to the auditors who audit you. If you are still evaluating us, you are not a user entity yet and the report is not something we can hand over, however much we would like the deal. And your client's auditor is a further step out again, because the customer in this arrangement is you rather than them.
Plenty of vendors read that legend loosely. We would rather tell you where the line is than send you a report your own auditor would tell you should not have been sent. What goes to a client or their auditor is the security page, written to be forwarded under your own cover note, plus the fact that the reports exist and the opinion is clean. If somebody needs a specific control answered for a questionnaire, ask us and we will answer it directly.
How to get the reports
Email partner@xop.ai with SOC report request in the subject line. They go out under NDA to customers, and to your own auditors when they are auditing you.
If your client's auditor needs coverage for the period since the examination closed, ask for that in the same email and we will tell you what we can provide.
