logo
|
Blog

    Tiro Achieves SOC 2 Type 2 Compliance

    Tiro Team's avatar
    Tiro Team
    Aug 03, 2026
    Tiro Achieves SOC 2 Type 2 Compliance
    Contents
    What is the difference between Type 1 and Type 2?Why we included all five criteria1. Security: Is the system protected against unauthorized access?2. Availability: Can customers use the service at the agreed level?3. Processing Integrity: Is processing complete and accurate?4. Confidentiality: Is confidential information handled only within its designated boundaries?5. Privacy: Is personal information handled as disclosed?Audit resultsOperating in a way that leaves evidenceThe work continues after the auditTiro Trust CenterAudit information

    Tiro has completed its SOC 2 Type 2 audit. Sensiba LLP, a U.S. audit firm, assessed Tiro’s security controls against standards established by the American Institute of Certified Public Accountants (AICPA), and Tiro received an unqualified opinion across all five Trust Services Criteria.

    When we announced our ISO/IEC 27001:2022 certification, we explained that Tiro views certification not as a one-time achievement, but as part of an ongoing process of improvement. This audit marks the next step in that process.

    In our previous announcement, we described how Tiro protects customer data: audio is deleted immediately after processing, customer conversations are not used to train AI models, data is encrypted both at rest and in transit, access is restricted according to the principle of least privilege, and all access and changes are logged.

    That was Tiro’s own description of how we operate. What has changed is that an independent auditor has now verified those same practices. The audit did not look only at how our controls were designed at a single point in time. It assessed whether they operated effectively throughout the entire audit period.

    The hardest part of security is not creating controls. It is proving that those controls are followed every day. The difference between controls that work as documented and controls that exist only on paper may remain hidden during ordinary operations, only to surface all at once when an incident occurs. A SOC 2 Type 2 audit examines that gap.

    What is the difference between Type 1 and Type 2?

    There are two types of SOC 2 reports.

    Type 1 evaluates design. It assesses whether controls are suitably designed and in place as of a specific date. For example, it examines whether access-control policies have been established, deployment approval procedures have been defined, and backup systems are in place. It is similar to a snapshot.

    Type 2 evaluates operations. In addition to design, it assesses whether those controls operated effectively throughout a defined audit period. Rather than asking only whether a policy exists, it asks whether that policy was followed consistently over the preceding months.

    This difference is clear in how the audit is conducted. Auditors do not stop after reading policy documents. They select samples from activities that actually occurred during the audit period. They examine access rights that were granted and revoked, code changes deployed to production, backup and recovery tests that were performed, and security events that were detected and handled. Each sample is checked against the relevant control to confirm that it operated as intended. If even one sample falls outside the control, the exception is recorded in the report.

    The resulting deliverable is also different. A Type 2 audit produces more than a single certificate. It produces an audit report describing what the auditor tested for each control and the outcome of those tests. A customer’s security review team can read the report directly and compare it against its own review requirements. Rather than receiving only a pass-or-fail result, the customer receives the evidence needed to make its own assessment.

    This is also why ISO/IEC 27001 and SOC 2 do not replace one another. ISO 27001 certifies that an information security management system conforms to an international standard. SOC 2 Type 2 documents, with supporting evidence, how individual controls within that system operated over a specific period. One demonstrates that the management system is suitably structured; the other demonstrates its operating history.

    Why we included all five criteria

    For a SOC 2 audit, an organization can choose which of the five Trust Services Criteria to include. Security is the only mandatory criterion. The remaining four are selected based on the nature of the service. Many companies are audited only against Security, or against Security plus one or two additional criteria.

    Tiro included all five. For a service that records meetings and conversations, every criterion corresponds to a real concern for customers. Below, we explain what each criterion evaluates and what it means for a service like Tiro.

    1. Security: Is the system protected against unauthorized access?

    Security is the common criterion that underpins the other four. It covers the full foundation of information security, including physical and logical access controls, change management, risk assessment, anomaly detection, incident response, and vendor management.

    Meeting notes contain organizational decisions, customer conversations, internal discussions, and future plans. The impact of exposing a single document is different from the impact of making an entire archive of meeting records accessible. At Tiro, security is therefore a question of how few paths can lead to customer data. The auditors tested whether controls existed along each path and whether those controls remained in place throughout the audit period.

    2. Availability: Can customers use the service at the agreed level?

    Availability assesses whether a system operates and remains accessible at the agreed level. It covers monitoring, incident response, backup and recovery testing, and capacity management.

    For a meeting-recording service, availability has a different character than it does for many other services. When most services experience an outage, users can return to the interrupted task after the service is restored. A meeting, however, does not happen again. If it is not recorded in the moment, there is no way to recover the conversation. When a customer turns on Tiro and starts a meeting, Tiro shares responsibility for not missing it. Including Availability in the audit scope means making that responsibility subject to independent verification.

    3. Processing Integrity: Is processing complete and accurate?

    Processing Integrity evaluates whether system processing is complete, accurate, timely, and performed only as authorized. It does not ask only whether data is stored securely. It examines whether the processing of that data is performed correctly.

    Meeting notes are often used more after they are created than at the moment of creation. Weeks later, they may be cited as the basis for a decision or shared with someone who did not attend as the only record of the meeting. If the content differs from the original conversation, that is not merely an error in a convenience feature. It is a matter of trust. For a meeting-recording service, the accuracy of its outputs is as important to trust as security. That judgment is why we included Processing Integrity in the audit scope.

    4. Confidentiality: Is confidential information handled only within its designated boundaries?

    Confidentiality assesses whether information designated as confidential is accessed only within defined boundaries and securely disposed of when its retention period ends. It applies to all information designated for restricted handling, whether or not that information qualifies as personal data.

    Much of what is discussed in meetings is confidential even when it is not personal data. Examples include plans that have not yet been announced, terms of ongoing contracts, and internal organizational discussions. Such information can create problems not only when leaked externally, but also when shared more broadly inside an organization than intended. The Confidentiality criterion therefore examines whether note-sharing permissions are enforced as configured, whether access ends when permissions are revoked, whether contracts limit what is shared with subprocessors, and whether data is actually disposed of after its retention period expires.

    5. Privacy: Is personal information handled as disclosed?

    Privacy assesses whether the collection, use, retention, disclosure, and disposal of personal information are consistent with what has been communicated. It is the only one of the five criteria that also follows a separate set of privacy principles.

    For a meeting-recording service, personal information extends beyond account information. A participant’s name, voice, and statements may all constitute personal information, including information about external participants who do not have a direct contract with Tiro. If Confidentiality asks “Who can see this?”, Privacy asks “Why was it collected, was it used only for the disclosed purpose, and are access and deletion requests actually fulfilled?” Our principle of not using customer conversations to train AI models was also reviewed by the auditors under this criterion.

    Audit results

    The audit report states that all five criteria were applicable to Tiro’s system and that none were excluded. Tiro received an unqualified opinion covering both the design of its controls and their operating effectiveness throughout the audit period. The report also states that, as of the end of the audit period, the service had experienced no material security incidents during the preceding 12 months.

    Operating in a way that leaves evidence

    Passing an audit requires more than having controls. There must also be records showing that those controls operated as intended. This is why Tiro approached audit readiness not as an exercise in producing documentation, but as a redesign of operations so that evidence is generated as part of everyday work.

    1. We separated production and development environments at the account level. Customer data cannot be accessed from the development environment, and organizational policies enforce the boundaries between accounts. This allows the team to experiment freely in an environment fully isolated from customer data.

    2. We aggregate audit logs from all accounts in a separate security account. Logs are stored in encrypted form and can be checked for tampering. Permissions are separated between the systems that generate logs and the system that stores them, preventing logs from being deleted in the event of an incident.

    3. All code going to production requires approval. Direct changes to the main branch are blocked, and the platform technically prevents unapproved merges. Each repository also specifies who must review which code.

    4. Most of our infrastructure is managed as code. Approximately 80% of the infrastructure supporting the Tiro service is defined as Infrastructure as Code (IaC), so every change goes through code review and leaves a record. The fact that the same configuration can be reproduced at any time is itself evidence that operations are controlled.

    5. We combine continuous detection with device controls. Threat detection, vulnerability scanning, and a web application firewall operate around the clock in our cloud environment. Team members’ work devices and accounts are managed through a unified authentication system and management tools.

    The status of these controls is continuously monitored through a compliance platform. If a configuration deviates from the required standard, it becomes visible immediately, even outside an audit period.

    The work continues after the audit

    SOC 2 Type 2 is an assessment of a completed audit period. Trust for the next period can be demonstrated only by the operating records from that next period.

    Tiro has engaged external security specialists Theori and KAOS Labs to conduct regular penetration tests. These are not superficial reviews: the specialists are given access to source code and infrastructure configurations. Any vulnerabilities they identify are remediated and then retested. We have also completed control mappings for CIS Controls v8.1, the NIST AI RMF, and the NIST CSF, enabling us to operate multiple frameworks through a single information security management system.

    The security environment continues to evolve. As recent incidents have shown, rapid advances in AI model capabilities are also making security threats more sophisticated. Tiro continues to review its service infrastructure and operating practices in response to these changes.

    We will continue to assess security risks and build a safer service environment so that customers can record and use their meetings with confidence.

    Tiro Trust Center

    Through the Tiro Trust Center, we publish information about our certifications, compliance frameworks, and subprocessors. The full SOC 2 audit report describes the testing procedures performed by the auditors for each control and the corresponding results. It is available through the Trust Center request process after a nondisclosure agreement has been signed.

    If you are conducting a security review or vendor assessment, please request the materials you need through the Trust Center or contact us at partners@theplato.io.

    Audit information

    Item

    Details

    Standard

    SOC 2 Type 2 (AICPA, TSP section 100 · 2017 Trust Services Criteria)

    Scope

    Security, Availability, Processing Integrity, Confidentiality, and Privacy (all five criteria)

    System audited

    ThePlato Inc. Software as a Service System (Tiro)

    Audit period

    April 1, 2026 to June 30, 2026

    Audit firm

    Sensiba LLP

    Audit opinion

    Unqualified Opinion

    The full audit report is available upon request through the Tiro Trust Center after a nondisclosure agreement has been signed.

    We will continue to assess security risks and build a safer service environment so that customers can record and use their meetings with confidence.

    Share article
    Contents
    What is the difference between Type 1 and Type 2?Why we included all five criteria1. Security: Is the system protected against unauthorized access?2. Availability: Can customers use the service at the agreed level?3. Processing Integrity: Is processing complete and accurate?4. Confidentiality: Is confidential information handled only within its designated boundaries?5. Privacy: Is personal information handled as disclosed?Audit resultsOperating in a way that leaves evidenceThe work continues after the auditTiro Trust CenterAudit information

    Tiro Blog

    RSS·Powered by Inblog