We started SOC 2 Type 2
And the certification itself is the least interesting part about it
Syncplify has started its SOC 2 Type 2 process. We’re running it with Oneleet.
Up till now, we simply didn’t need one. We sold software you downloaded and ran yourself. Your files sat on your servers. Your users lived in your directory. Your logs stayed on your disk. We had nothing of yours to protect, so there was very little for an auditor to look at, and a report confirming that we held no customer data would have been an expensive way to state the obvious.
But we’re about to launch SFTP.cloud now, and that makes everything more interesting. It is a service we operate, which means we now have uptime to be responsible for, access to our own systems to control, people to vet, and changes to manage. Those are fair questions and customers must be given the answers without having to ask them.
Here’s the wrinkle, and we rather like it: we still don’t have your files. SFTP.cloud is built so that customer data stays in customer storage, and so that we never hold the credentials to reach it. A good portion of what a SOC 2 report usually existsfor still doesn’t apply to us. What’s left is how we run the service, and that is exactly the part we want examined.
Now the part we’re less polite about
We have a low opinion of compliance as an idea. It shares more than a first syllable with complacency. A framework is an easy thing to perform rather than practice, and a certificate has never once stopped a vulnerability from shipping.
We started this because the work has value on its own. Writing down how you actually do things, and then finding all the places where you don’t, is useful whether or not somebody checks afterwards. Access reviews you can’t quietly skip. Change management that leaves a trail. Onboarding and offboarding that run the same way every time instead of the way whoever was free that afternoon remembered it.
We have done most of this for years. Doing it in a standardized form that a third party can inspect is a different beat altogether, and it can make us better.
If the certificate turns out to be the least interesting thing we get out of this, that will be the right outcome.
What happens next
The Type 2 observation window runs for months. We’ll publish the report when we have it, and we’ll write about what we learned, including the parts that were uncomfortable (if any).
Until then, nothing about how SFTP.cloud is built depends on any of this. Your files are still yours, still in your storage, still reachable only with credentials we never see.

