Reference
SOC 2 Glossary
Plain-English explanations of the SOC 2 and AICPA terms you will run into inside Polara. If a term is missing, email founder@polaralabs.com and we will add it.
Trust Services Criteria (TSC)
The five buckets SOC 2 measures you against: Security, Availability, Processing Integrity, Confidentiality, Privacy.
In Polara: Whatever you check in the scoping step becomes your scope. Security is always in. The rest are optional based on what you actually owe customers.
Where you will see it: Intake scoping, dashboard scope card, policies, final report.
Security (Common Criteria)
The baseline of SOC 2. Protects systems and data from unauthorized access. Every SOC 2 engagement includes it.
In Polara: We always score you against the Common Criteria (CC1 through CC9). You cannot opt out of Security.
Where you will see it: Intake scoping, every gap and policy, Section 3 of the report.
Availability
You commit to customers that the system stays up. This TSC covers uptime, backups, and disaster recovery.
In Polara: Check this if your customer contracts have SLAs or uptime promises. Adds BCP and DR controls on top of Security.
Where you will see it: Intake scoping, BCP and DR policies, monitoring evidence, report.
Confidentiality
Business data your customers expect you to keep private: contracts, source code, financials, anything covered by an NDA.
In Polara: This is the right answer for most B2B SaaS. If your customers send you confidential business data, add this.
Where you will see it: Intake scoping, data protection policy, report.
Privacy
Personal information about individual people, not business data. This is heavy: GDPR-style rights, notices, consent.
In Polara: Only add this if you actively collect personal data beyond basic account info. Most startups want Confidentiality, not Privacy.
Where you will see it: Intake scoping, privacy notice, data subject request policy, report.
Processing Integrity
The system processes things correctly, on time, and only the things it is supposed to. Think payments, billing, data pipelines.
In Polara: Add this if you run financial transactions or critical processing on behalf of customers. Skip it if you are a generic SaaS tool.
Where you will see it: Intake scoping, processing controls, monitoring evidence, report.
Complementary User Entity Controls (CUEC)
Stuff your customers have to do on their end for your controls to actually work. Example: if MFA only works when they turn it on, that is a CUEC.
In Polara: We list these in your report so auditors and customers know where your system ends and customer responsibility starts.
Where you will see it: Report Section 3 description, Appendix, sometimes in policies.
Complementary Subservice Organization Controls (CSOC)
Stuff your vendors (AWS, Supabase, Stripe) have to do so your controls hold up. You rely on them, so the auditor wants them named.
In Polara: We list your subservice orgs and which of their controls you depend on. You do not audit them, you just identify the dependency.
Where you will see it: Report Section 3 description, vendor inventory.
Point of Focus (PoF)
A sub-example inside a criterion that shows one way to meet it. The AICPA lists 221 of them across all TSCs.
In Polara: We map your controls to Points of Focus so the auditor can see your coverage fast. You do not have to hit every PoF, just the criterion.
Where you will see it: Behind the scenes in our scoring, and in the auditor package.
Attestation Engagement
The legal framework a CPA uses for SOC 2. Not an audit, not a review. It is its own thing under AT-C 205.
In Polara: We say "audit" in the product because everyone says it. Technically your CPA is running an attest engagement.
Where you will see it: Auditor engagement letter, report cover page.
Management's Assertion
A signed statement from your side saying the system description is accurate and the controls exist and work.
In Polara: You (or your signatory) sign this before the auditor issues their opinion. We draft it for you.
Where you will see it: Report Section 2, signed PDF in the final package.
Service Auditor's Opinion
The CPA firm signs this. Four possible flavors: unmodified (clean), qualified (mostly good), adverse (bad), disclaimer (cannot opine).
In Polara: This is what your customers actually care about. We prepare everything so the auditor can issue an unmodified opinion.
Where you will see it: Report Section 1, the first thing every reader flips to.
Signatory
The person at your company who signs management's assertion. Usually the CEO, CTO, or head of security.
In Polara: We collect the signatory in onboarding. They get the DocuSign request when it is time to sign.
Where you will see it: Onboarding, assertion signature block, report cover.
Period of Observation
The window of time a Type 2 report covers. Typically 3 to 12 months. The auditor checks that controls ran consistently across it.
In Polara: For Type 2 buyers, we set this during onboarding and run monthly check-ins across the window. Type 1 does not have one.
Where you will see it: Type 2 intake, observation dashboard, report Section 1.
As-of Date
The single point in time a Type 1 report covers. The auditor says "as of this date, controls were designed right."
In Polara: For Type 1 we pick the as-of date together and generate the report to match. Type 2 uses an observation period instead.
Where you will see it: Type 1 report cover, assertion, auditor opinion.
Segregation of Duties (SoD)
No single person can do a risky thing end to end. Example: the dev who writes code does not also push it to prod unreviewed.
In Polara: We flag SoD gaps in your access and change management controls. Small teams get compensating controls instead of hard splits.
Where you will see it: Access control policy, change management policy, gap list.
Missing a term or want a different explanation?
Email founder@polaralabs.com