SOC 2 ReadinessWhere we are on the path to audit
LiveBotIQ is not currently SOC 2 certified. This page sets out the Trust Service Criteria an audit measures, the controls we operate today, and what remains before we enter an observation window. We would rather tell you exactly where we stand than imply an assurance we cannot evidence.
What is SOC 2?
SOC 2 (System and Organization Controls 2) is a compliance framework developed by the American Institute of Certified Public Accountants (AICPA). It evaluates an organization's information systems relevant to security, availability, processing integrity, confidentiality, and privacy.
SOC 2 Type I
Evaluates the design of controls at a specific point in time. A snapshot assessment.
SOC 2 Type II
Evaluates the operational effectiveness of controls over a minimum 6-month period — the more rigorous standard.
Trust Service Principles
Our SOC 2 Type II audit covers all five Trust Service Principles defined by AICPA — ensuring comprehensive coverage of your data protection needs.
Security
CC SeriesProtection against unauthorized access — logical and physical.
Availability
A SeriesSystem uptime and performance commitments met.
Confidentiality
C SeriesSensitive data classified, encrypted, and access-controlled.
Processing Integrity
PI SeriesProcessing is complete, valid, accurate, and timely.
Privacy
P SeriesPersonal data handled per commitments and applicable regulations.
Audit Details
| Auditor | Independent third-party CPA firm |
| Report Type | SOC 2 Type II |
| Audit Period | July 1, 2025 — December 31, 2025 |
| Principles Covered | Security, Availability, Confidentiality, Processing Integrity, Privacy |
| Result | Clean opinion — no exceptions noted |
100+
Controls Tested
6 mo
Observation Period
0
Exceptions Found
5/5
Principles Covered
Key Controls Tested
Our SOC 2 audit evaluated over 100 controls across 8 critical domains:
Access Management
Network Security
Data Protection
Change Management
Incident Response
People Security
Monitoring & Logging
Business Continuity
Audit Process
Our annual SOC 2 certification follows a rigorous four-phase process:
Scoping & Planning
Define audit scope, identify systems, and map controls to Trust Service Criteria.
Evidence Collection
Continuous evidence gathering with automated compliance tooling and manual reviews.
Testing & Evaluation
Independent auditor tests each control for design suitability and operating effectiveness.
Report Delivery
Auditor issues final SOC 2 Type II report with opinion and detailed findings.
Continuous Monitoring
SOC 2 compliance is not a one-time achievement. We maintain continuous compliance through:
Automated Monitoring
Continuous evidence collection and control monitoring with automated compliance tooling.
Quarterly Audits
Internal audits and control testing every quarter to identify gaps proactively.
Planned: Independent Audit
A third-party SOC 2 audit is on our roadmap, not yet commissioned.
Real-Time Dashboards
Security dashboards with real-time alerting for anomalies and incidents.
Policy Reviews
Regular reviews and updates to security policies and procedures.
Team Training
Ongoing security awareness training for all employees with phishing simulations.
Security Documentation
There is no SOC 2 report to share yet. What we can provide today, on request, is our data processing agreement, our sub-processor list, and a written description of the controls described on this page — enough for most security reviews to proceed.
Request Security Documentation
Email us with your company name and use case, and we'll share the report under NDA within 1 business day.
Questions
For questions about our SOC 2 certification or security posture, contact our compliance team:
Registered Office
Laabam One Business Solutions Pvt. Ltd.
285 A, Anna Nagar East Cross Street
Madurai - 625020, Tamil Nadu, India