We’re SOC 2 Type II certified
ZEDai maintains compliance with SOC 2 Type II requirements and undergoes annual SOC 2 Type II certification for GovFolio. Our services are hosted in SOC 2 Type II-certified data centers.
What Is Audited Annually
To achieve this SOC 2 Type II certification, the following are audited annually:
- Data Center: The physical facility, security and environmental controls and operations.
- Infrastructure: Power, network, and systems security and availability.
- Software: Application development, provisioning and support controls and operations.
- People: The personnel involved in the operation and use of systems and applications.
- Procedures: The automated and manual procedures involved in the operation of systems and applications.
- Data: Security protocols and controls of data used and managed in the systems and applications.
What Is SOC 2?
The Service Organization Control (SOC) 2 examination demonstrates that an independent auditing firm has reviewed and examined an organization’s control objectives and activities and tested those controls to ensure they operate securely and effectively.
- Developed by the American Institute of CPAs (AICPA), SOC 2 defines criteria for managing customer data. Certifications assess compliance with five trust categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
- Type I vs. Type II: Type II reports are issued to organizations with audited controls whose effectiveness has been tested over time. Type I reports are preliminary, based on control design ability.

Why Is SOC 2 Type II Important to Our Clients and Their Customers?
It provides a level of confidence and comfort. By working with a SOC 2 Type II certified organization, users ensure that data is kept secure through the consistent implementation of standardized controls.
How Does It Impact Data Center Infrastructure?
Data center services such as managed services, hosting, and colocation developed by a SOC 2 certified organization must be developed following audited processes and controls. Services designed, implemented, tested, and monitored under these audited processes and controls ensure the highest level of trust and security.
How Does It Impact Software?
Software developed by a SOC 2 certified organization must be developed following audited processes and controls. Software developed, reviewed, tested, and released under these audited processes and controls ensures the highest level of trust and security.