Security claims are easy to publish. Independent evidence is harder to produce. Gov2Biz undergoes a SOC 2 Type II examination every year so customers can evaluate how our controls operate over time, not merely how they are described on paper.
Government technology decisions rarely belong to one team. Security may examine controls. Privacy may review data use. Technology leaders may evaluate architecture and resilience. Legal and procurement may test whether promises are precise and supportable.
Independent assurance gives those reviewers a shared foundation. It does not replace an agency's risk assessment, but it helps the evaluation begin with tested evidence rather than marketing language alone.
Gov2Biz's current SOC 2 Type II examination evaluated the design and operating effectiveness of controls relevant to all five AICPA Trust Services Criteria categories:
The report, issued in May 2026, covers April 16, 2025 through April 15, 2026. No exceptions were noted.
The examination was based on the 2017 AICPA Trust Services Criteria, including the revised points of focus issued in 2022.
The phrase is deliberately precise. It means the independent examination did not identify exceptions in testing the controls covered by the report during the examination period.
It does not mean risk disappears, that incidents are impossible, or that every customer requirement is automatically satisfied. It means your reviewers have a clean examination result to assess alongside the scope, system description, complementary responsibilities, and their own requirements.
The SOC 2 report includes restricted information about the Gov2Biz system and control environment, so it is not posted publicly.
Qualified organizations involved in an active procurement can request the current report under NDA. This gives legitimate reviewers access to meaningful evidence without exposing sensitive operational details to the open internet.
Request Security DocumentationClear scope matters as much as strong controls. Gov2Biz does not treat every framework, hosting decision, or procurement relationship as interchangeable.
Gov2Biz is hosted in AWS GovCloud (US). AWS compliance programs can support the infrastructure layer, but they do not automatically make Gov2Biz FedRAMP authorized or compliant with every government framework.
Requirements such as FedRAMP, StateRAMP, CJIS, or agency-specific standards must be evaluated against the defined system, data, deployment, control responsibilities, evidence, and required approval process.
Contract vehicles, schedules, reseller relationships, and marketplace listings can make a product easier to buy. They do not prove that a security control was designed or operated effectively. Gov2Biz presents procurement channels separately from independent assurance so buyers can distinguish purchasing convenience from control evidence.
Gov2Biz does not collect or process cardholder data within its environment. When a user makes a payment, Gov2Biz redirects the user to a third-party payment provider, which collects and processes the cardholder data.
This separation narrows the Gov2Biz payment-data boundary. Each agency should still evaluate the complete payment flow, its provider relationship, and the PCI DSS responsibilities applicable to its implementation.
SOC 2 is an attestation examination, not a certification. The accurate statement is that Gov2Biz completes a SOC 2 Type II examination annually.
The current examination covered Security, Availability, Processing Integrity, Confidentiality, and Privacy.
The current report covered April 16, 2025 through April 15, 2026. No exceptions were noted.
Qualified organizations participating in an active procurement can request it. Gov2Biz provides the report under NDA after reviewing the request.
No. Users are redirected to third-party payment providers that collect and process cardholder data outside the Gov2Biz environment.
No. Cloud hosting alone does not confer an application authorization. Any authorization or compliance claim must be evaluated against its exact scope and evidence.
Request the current SOC 2 Type II report and other available security documentation for your active Gov2Biz evaluation.