SOC 2 is an attestation framework defined by the AICPA (the American Institute of Certified Public Accountants). In a SOC 2 Type II engagement, an independent CPA firm examines a company's controls against the Trust Services Criteria — areas such as security and availability — and, critically, tests whether those controls operated effectively over a sustained audit period, not just on a single day. That is the difference from a Type I report, which only assesses control design at a point in time.
For a buyer, a current Type II report means an outside auditor has repeatedly observed the vendor's security practices working in production over months, and has documented any exceptions found. HelloGrowthCRM's attestation covers security, availability, and confidentiality controls for the production CRM platform and AI services, over a 12-month audit period refreshed annually. The full report — with the auditor's opinion, control descriptions, and test results — is available under NDA through the Trust Center.