Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Trust Center / Compliance

Security claims are easy to publish. Independent evidence is harder to produce. Gov2Biz undergoes a SOC 2 Type II examination every year so customers can evaluate how our controls operate over time, not merely how they are described on paper.

01

Give every stakeholder a common body of evidence

Government technology decisions rarely belong to one team. Security may examine controls. Privacy may review data use. Technology leaders may evaluate architecture and resilience. Legal and procurement may test whether promises are precise and supportable.

Independent assurance gives those reviewers a shared foundation. It does not replace an agency's risk assessment, but it helps the evaluation begin with tested evidence rather than marketing language alone.

02

Annual SOC 2 Type II examination

Gov2Biz's current SOC 2 Type II examination evaluated the design and operating effectiveness of controls relevant to all five AICPA Trust Services Criteria categories:

Security: protection against unauthorized access, use, or disclosure
Availability: operation and accessibility according to commitments
Processing Integrity: complete, valid, accurate, timely, and authorized processing
Confidentiality: protection of information designated as confidential
Privacy: handling of personal information according to relevant commitments

The report, issued in May 2026, covers April 16, 2025 through April 15, 2026. No exceptions were noted.

The examination was based on the 2017 AICPA Trust Services Criteria, including the revised points of focus issued in 2022.

03

What “no exceptions noted” tells a buyer

The phrase is deliberately precise. It means the independent examination did not identify exceptions in testing the controls covered by the report during the examination period.

It does not mean risk disappears, that incidents are impossible, or that every customer requirement is automatically satisfied. It means your reviewers have a clean examination result to assess alongside the scope, system description, complementary responsibilities, and their own requirements.

04

Review the report during an active procurement

The SOC 2 report includes restricted information about the Gov2Biz system and control environment, so it is not posted publicly.

Qualified organizations involved in an active procurement can request the current report under NDA. This gives legitimate reviewers access to meaningful evidence without exposing sensitive operational details to the open internet.

Request Security Documentation
05

Keep compliance boundaries honest

Clear scope matters as much as strong controls. Gov2Biz does not treat every framework, hosting decision, or procurement relationship as interchangeable.

AWS GovCloud is a foundation, not an automatic authorization

Gov2Biz is hosted in AWS GovCloud (US). AWS compliance programs can support the infrastructure layer, but they do not automatically make Gov2Biz FedRAMP authorized or compliant with every government framework.

Requirements such as FedRAMP, StateRAMP, CJIS, or agency-specific standards must be evaluated against the defined system, data, deployment, control responsibilities, evidence, and required approval process.

Procurement access is not a security certification

Contract vehicles, schedules, reseller relationships, and marketplace listings can make a product easier to buy. They do not prove that a security control was designed or operated effectively. Gov2Biz presents procurement channels separately from independent assurance so buyers can distinguish purchasing convenience from control evidence.

06

Reduce payment risk through separation

Gov2Biz does not collect or process cardholder data within its environment. When a user makes a payment, Gov2Biz redirects the user to a third-party payment provider, which collects and processes the cardholder data.

This separation narrows the Gov2Biz payment-data boundary. Each agency should still evaluate the complete payment flow, its provider relationship, and the PCI DSS responsibilities applicable to its implementation.

Frequently asked questions

SOC 2 is an attestation examination, not a certification. The accurate statement is that Gov2Biz completes a SOC 2 Type II examination annually.

The current examination covered Security, Availability, Processing Integrity, Confidentiality, and Privacy.

The current report covered April 16, 2025 through April 15, 2026. No exceptions were noted.

Qualified organizations participating in an active procurement can request it. Gov2Biz provides the report under NDA after reviewing the request.

No. Users are redirected to third-party payment providers that collect and process cardholder data outside the Gov2Biz environment.

No. Cloud hosting alone does not confer an application authorization. Any authorization or compliance claim must be evaluated against its exact scope and evidence.

Give your review team the evidence behind the claims

Request the current SOC 2 Type II report and other available security documentation for your active Gov2Biz evaluation.