Every venue now runs on software. Your event leads, guest conversations, contracts, payment details, and calendars all live in systems built by other companies. Which means every vendor you sign is also a decision about who you trust with your guests’ information.
SOC 2 is one of the most useful tools you have for making that decision well. Here is what it actually is, in plain language.
SOC 2 is part of the System and Organization Controls framework maintained by the American Institute of Certified Public Accountants (AICPA), the body that governs the auditing profession in the United States. A SOC 2 examination is performed by an independent CPA firm, under the AICPA’s audit and assurance standards, against a set of criteria covering security and related areas like availability and confidentiality.
The output is not a badge a company awards itself. It is a detailed report, written by outside auditors, describing the company’s controls: how access is granted and revoked, how data is protected, how changes to systems are managed, how incidents are handled, and how vendors of the vendor are vetted.
A Type I report examines whether a company’s controls are suitably designed at a point in time. A Type II report goes further and tests whether those controls operated effectively over a period of months. Companies typically complete a Type I first and a Type II after the controls have run for an observation period. Both are real, independent examinations; they answer different questions.
Hospitality does not always think of itself as a data business, but an events operation handles names, phone numbers, email addresses, event details, and payment information for thousands of guests a year. Agencies like CISA publish baseline practices for exactly this reason: most breaches exploit ordinary gaps in access control and process, not exotic attacks. The NIST Cybersecurity Framework makes the same point from the other direction: security is a set of everyday operational disciplines, and the organizations that write them down and audit them are the ones that keep them.
When a vendor has been through a SOC examination, someone outside the company has verified that those disciplines exist. When a vendor has not, you are taking their word for it.
You do not need to be a security expert to run a good vendor review. Four questions get you most of the way:
First, have you completed a SOC 2 examination, and is it Type I or Type II? Second, can you share the report under NDA with our IT or procurement team? Third, who inside your company can see our data, and how is that access controlled? Fourth, what happens to our data if we leave?
A serious vendor answers all four without flinching. Hesitation on any of them tells you something too.
Hermetic AI has completed a SOC 2 Type I examination, an independent report on the design of our security controls. Guest conversations and lead data are handled under those controls, and the report is available to your security or procurement team as part of a review. It is the same standard we would tell you to hold any vendor to, so it is the standard we hold ourselves to.
More detail lives in our FAQ, and if your team wants to walk through it with us, book a demo and bring your IT questions along.