SOC 2 Type II is in progress. The audit window is H2 2026 (the second half of 2026), and Drata-managed continuous monitoring is live now — the controls SOC 2 Type II measures are running and being evidenced day-to-day. The formal attestation report follows the audit. Evolution Global publishes the current status on the Trust Center, and the report itself will be available behind the Drata Trust Center under NDA when issued.
What SOC 2 actually measures
SOC 2 (Service Organization Control 2) is the AICPA's framework for evaluating how a service organization handles customer data across five Trust Service Criteria:
Security — protecting against unauthorized access, both physical and logical.
Availability — making the system reachable and operational.
Processing Integrity — ensuring processing is complete, valid, accurate, timely, and authorized.
Confidentiality — protecting information designated as confidential.
Privacy — handling personal information consistent with the entity's privacy notice and the AICPA's Generally Accepted Privacy Principles.
Most cloud-software vendors evaluate against Security at minimum, often Availability and Confidentiality alongside.
Type I vs Type II — and why we're going to Type II
SOC 2 has two report types:
Type I — describes the organization's controls at a single point in time. Useful but weaker — it confirms the controls exist on the audit date.
Type II — describes the organization's controls and tests their operating effectiveness over a period (typically 6–12 months). Stronger — it confirms the controls actually work consistently across the audit period.
Evolution Global is going directly to Type II rather than starting with Type I. The standard pattern in the industry is to issue Type I first to get a SOC 2 report on the table quickly, then come back later for Type II. The trade-off for that speed is a less-meaningful report. We chose to wait through the audit window to issue a Type II first.
Where Evolution Global is now
Audit window: H2 2026.
Drata-managed continuous monitoring: live now. Drata is the platform that automates SOC 2 evidence collection — every control tagged to the framework is being evidenced day-to-day rather than reconstructed at audit time.
Controls in scope:
Identity and access (multi-factor authentication, role-based access controls, audit logs)
Encryption (in transit and at rest)
Change management (deployment review, code review, separation of duties)
Incident response and business continuity
Vendor management (subprocessor oversight, due diligence)
Personnel and access lifecycle (onboarding, offboarding, periodic review)
Customer data handling and the AI-specific controls under ISO 42001 and NIST AI RMF
Status published: the Trust Center page on the website carries the current state.
How prospects access the report when it's issued
Two paths:
Drata Trust Center — the SOC 2 report and supporting evidence will be posted behind the Drata Trust Center, accessible to prospects and customers under NDA. Request access through the demo conversation.
Master Service Agreement — the MSA references the SOC 2 status and incorporates DPA terms.
Why H2 2026
A SOC 2 Type II audit needs an operating period of evidence. You can't audit controls that haven't been running long enough to demonstrate consistency. Drata-managed continuous monitoring went live earlier in 2026; H2 2026 is the audit window where the auditor evaluates the evidence collected over the operating period.
A faster path — Type I report at an earlier point — was an option. We chose against it because the brand commitment on this kind of work is "we ship in public, milestones not promises." A Type II at H2 2026 is more meaningful than a Type I at an earlier date.
What sits alongside SOC 2
ISO 42001 (AI management) — Active.
NIST AI Risk Management Framework — Mapped and operational.
CIS v1.0 (Certified Integrity Standard) — Active. Evolution Global is Ark-Certified Company No. 001.
GDPR / CCPA / CPRA / VCDPA / TDPSA — Compliant.
Zero Data Retention agreements with Anthropic, OpenAI, Google — Active.
SOC 2 isn't the whole story. It's the most familiar audit framework for enterprise IT teams; the AI-specific frameworks (ISO 42001, NIST AI RMF, CIS) are the ones that actually govern how ELIAS AI is built and operated. SOC 2 covers the IT-controls layer; the AI frameworks cover the AI-governance layer.
Related questions
How secure is FileTrac — what's your security and compliance posture?
How does FileTrac handle claims data privacy and HIPAA-relevant information?
What's your AI strategy, and how does ELIAS work inside FileTrac?
Is my data being used to train AI models — yours or anyone else's?
Do you have penetration testing reports I can review under NDA?
