We achieved SOC 2 Type 2 attestation covering Security, Confidentiality, and Availability — independently audited by Accorp Partners CPA LLC over a 6- month observation period.
Trust Service Criteria
Three criteria. All passed.
Our SOC 2 Type 2 audit covered three of the five Trust Service Criteria — the ones most relevant to an MSP support and technology services business.
🔒
Security
🔐
Confidentiality
⚡
Availability
Official Attestation
The auditor's opinion
Our SOC 2 Type 2 report was issued by Accorp Partners CPA LLC, an independent CPA firm in North Hollywood, California. Their auditors reviewed our controls, tested procedures, and issued a formal attestation opinion for the full six-month period.
📋
SOC 2 Type 2 Attestation Report
Accorp Partners CPA LLC · October 10, 2025
Subject
Inputiv LLP — tech consulting controls relevant to Security, Confidentiality and Availability Trust Service Criteria
Audit Period
April 1, 2025 — September 30, 2025
Report Type
SOC 2 Type 2 (Operational Effectiveness over sustained period)
Auditor
Accorp Partners CPA LLC
License: PAC-FIRM-LIC-47383 · North Hollywood, CA 91601, USA
Auditor Opinion (a)
✓ The description presents Inputiv's system that was designed and implemented throughout the period in accordance with the description criteria.
Auditor Opinion (b)
✓ The controls were suitably designed throughout the period to provide reasonable assurance that Inputiv's service commitments would be achieved.
Auditor Opinion (c)
✓ The controls operated effectively throughout the period to provide reasonable assurance that Inputiv's service commitments were achieved.
Controls We Implemented
What we did to earn this
Achieving SOC 2 Type 2 required formalising and evidencing controls across every aspect of how we operate. These aren't checkbox exercises — they're the same proven controls that protect our clients' environments every day and support secure, reliable service delivery.
✓
Access Control Reviews
Quarterly reviews of all logical access to client systems, tools, and internal platforms.
✓
Information Security Policy
Published policy covering data handling, incident response, and acceptable use.
✓
Incident Response Plan
Documented and tested incident response procedure — tested twice during the audit period.
✓
Vendor Risk Management
Documented third-party vendor assessment process covering all tools with client data access.
✓
Security Event Monitoring
Automated alerting for all key security events across internal systems and client- facing tools.
✓
Security Awareness Training
Annual security training completed by all engineers,with completion records.
✓
Data Encryption Standards
Data encrypted in transit (TLS 1.2+) and at rest (AES-256) across client systems and internal platforms.
✓
Change Management Process
All changes approved before deployment - rollback procedures tested quarterly.
✓
Business Continuity Plan
Documented BCP for service disruptions, recovery objectives, and failover testing.
✓
Security Penetration Testing
Annual third-party penetration testing of external systems, with remediation tracking.
Certification Timeline
Six-month observation period, report issued October 2025.
Why This Matters for MSPs
Your clients should know
their support partner is certified
When you work with Inputiv— for helpdesk, project delivery, or the TBR platform — you're working with a partner whose security controls have been independently verified over six months. Here's what that means in practice.
🛡️
Cyber Insurance
Cyber insurers increasingly audit vendor security posture during renewals. Working with a SOC 2 Type 2 certified support partner strengthens your own insurance position and may improve your questionnaire responses.
🏢
Enterprise Clients
Larger client organisations — especially in healthcare, legal, and financial services — often require their entire supply chain to meet security certification standards. Inputiv's SOC 2 helps you win and retain these accounts.
📋
Compliance Frameworks
MSPs whose clients require compliance with HIPAA, SOC 2, or ISO 27001 can now
reference their support partner's independent certification as part of their own vendor management documentation.