What SOC 2 taught a small team about trust
SOC 2 looks like a large-company problem until your first enterprise prospect asks for the report. This post walks through what a small team actually had to build to get through a Type I audit: access reviews, incident response plans, vendor assessments, and change management. The audit itself was the easy part. The clarity it produced about internal operations, risk, and customer trust was the lasting payoff.
Security has a way of hiding in plain sight. Everyone knows the rules, people follow them, and the people who built the systems carry a lot of it in their heads. That works until a customer's procurement team sends you a 200-question security review and asks you to prove it (and I've done my fair share of these).
That's the gap SOC 2 closes. I'm proud to share that Klipfolio has achieved a SOC 2 Type I attestation, completed by AssurancePoint. An independent auditor has examined how our key controls are designed and confirmed they align with the AICPA's Trust Services Criteria.
I want to tell you how we got here, because the process mattered as much as the result.
Starting with a framework, not a checklist
We didn't start by asking "what does the auditor want to see?" We started with the NIST Cybersecurity Framework, which we updated to version 2.0 this year as the backbone of our Cybersecurity Standards.
NIST gives us a way to think about security as a whole system: govern, identify, protect, detect, respond, recover. From there, we mapped each of our controls to the specific SOC 2 criteria it satisfies. When we say "networks and physical environments are monitored," that statement ties directly to SOC 2 criteria CC7.2 and CC6.6. When we say "external service provider activity is monitored," that ties to CC9.2, CC6.2 and CC6.3.
That mapping is the quiet hero of this whole effort. Every control has a reason to exist, and every SOC 2 requirement has a control behind it.
The hardest design problem: friction
The executive team and I spent real time on one question: how much security is the right amount for a company our size?
Klipfolio needs to move quickly. If a control slows people down without a clear reason, they'll find a way around it. And a workaround is often riskier than having no control at all. At the same time, our customers trust us with their business data, and that trust has to be earned in ways we can demonstrate.
So we made a deliberate choice. Our controls should be clean, formal and consistent, with the lightest touch that's still effective. As a small organization, many of our controls can be applied with human judgment rather than heavy automation, as long as the risks are fully understood. That's not a shortcut. It's a design decision, and we documented it so it can be reviewed like any other.
Working with an outside eye
It's easy to believe your own story. Having AssurancePoint come in and test that story against the Trust Services Criteria was humbling in the best way.
One thing they pushed us on early: doing the right things wasn't enough. We needed to be able to prove we were doing them. That distinction changed how we work. AssurancePoint helped us build evidence-gathering requirements into our day-to-day operations — not as a pre-audit scramble, but as a continuous habit. We added policies, updated existing ones, and created clear expectations around what documentation needs to exist and when.
They also helped us avoid a trap we might have walked into on our own. When you're writing controls, there's a temptation to be very specific about how something gets measured. That precision feels rigorous, but it can lock you in. If the method changes — a tool gets replaced, a process evolves — a tightly worded control can become inaccurate before the ink is dry. AssurancePoint helped us write controls that capture the intent and outcome without being so prescriptive that we'd be rewriting them every time something shifted. The result is a program that stays accurate as the business moves.
What changes day to day
SOC 2 isn't a certificate you frame and forget. A few things are now permanent parts of how we operate.
Our security policies are reviewed, updated and approved every year. We make sure audit trails and access logs are in place and good enough to detect and respond to both insider and outside threats. We monitor the vendors and service providers we depend on, because your data's safety depends on their practices as well as ours. And when something happens at a third party that touches us, we log it, track it and follow it through to corrective action.
The threat landscape keeps shifting, too. State-sponsored actors increasingly use social engineering and phishing to target small but widely used software libraries. A framework-based program lets us adapt to threats like that without rebuilding from scratch.
What this means for you
If you're a Klipfolio customer:
-
Easier vendor reviews. Your security and procurement teams can reference a formal SOC 2 report during due diligence instead of working through questionnaires line by line.
-
Independent assurance. You don't have to take our word for how we handle your data. An auditor has reviewed the design of our controls.
-
A program that keeps working. Monitoring, annual reviews and continuous improvement are built into how we operate.
A Type I attestation confirms our controls are well designed at a point in time. It's an important milestone, and we're treating it as a foundation, not a finish line.
Create custom dashboards for you and your team.
Get started with KlipsThank you
This took the whole company. Thank you to the executive team for backing a program that balances speed and rigor, to AssurancePoint for a thorough and fair assessment, and to every Klipfolian who wrote documentation, answered questions and changed habits along the way.
Trust is a core feature. We intend to keep shipping it.
Published 2026-09-25
More to read
Top cybersecurity KPIs to track for risk mitigation
Why every digital marketer needs to learn how to deploy marketing technology
Thriving in a tempest: What we learned about product management during Klipfolio's start-up phase
Proposal writing: A complete guide to winning more deals
Think in Horizons, Not Seconds
Misleading statistics and data: how to protect yourself against bad statistics
Most recent
- SEP 15The AI race: progress, humanity, and trust
- SEP 9The good advisor
- AUG 11Beyond simple sign-ups: how True Trials and Activation predict growth
- JUL 7Why business leaders miss important trends in their dashboards
- JUN 19The best chart for the job: Visualizing data for non-technical users
- JUN 95 tips to understand (and organize) your restaurant data