Skip to main content
PressSOC 2 Type IIEdTech ComplianceDefenseFERPAAttestation

First Pass, No Exceptions: Rise’s SOC 2 Type II, and an Air Force Contract for EDLORE

In one week, two systems our engineers build were validated by parties who do not take our word for anything: EDLORE won a U.S. Air Force contract, and Rise completed its first SOC 2 Type II examination with an unqualified opinion and no exceptions noted. Here is what that second sentence actually means, and why the phrase most companies use for it is wrong.

H2Om.AI Team · Compliance & Engineering Experts
9 min read

In the space of one week, two systems built by H2Om.AI engineers were validated by parties who do not take our word for anything.

EDLORE, the industrial 3D and augmented-reality platform used for asset management and maintenance, won a U.S. Air Force contract. And Rise, the school operations platform we have architected and built from its first line of code, completed its first SOC 2 Type II examination with an unqualified opinion and no exceptions noted.

Neither of those is a marketing claim. One is a procurement decision made by the United States Air Force. The other is the written professional opinion of an independent CPA firm, in a report a customer's security team can request and read line by line. That distinction is the whole point of this post.

// The examination, in numbers
3

Trust services criteria in scope: Security, Availability and Confidentiality

0

Exceptions noted by the examiner, on the first examination

Two validations, one week

EDLORE and the U.S. Air Force

EDLORE makes 3D interactive instructions software for digital asset management, or in its own considerably better phrasing, it exists because "Augmented 3D is worth 1,000 pictures." Its product line spans asset exploration, asset tracking and a remote expert capability that lets a specialist see what a technician on the ground is looking at.

That matters most in exactly the environment the Air Force operates in: complex equipment, distributed technicians, procedures that must be executed identically every time, and a very high cost for getting a step wrong. EDLORE already lists Air Force and Navy work among its industrial deployments alongside transportation, automotive, construction and OEM customers.

Rise and the SOC 2 Type II

Rise is the platform built specifically for hybrid, online and independent study schools. Its core product pulls the student information system, learning management, gradebooks, testing tools, communications, enrollment data and device inventory into a single real-time dashboard. Rise puts its reach at more than a thousand institutions.

Read that list again from a security perspective. Attendance. Grades. Coursework. Enrollment records. Dual enrollment and AP or IB exam data. Parent and teacher communications. Device inventory. That is a concentration of student records substantial enough that any serious district or charter network is going to ask a hard question before signing: prove the controls you say you run actually ran.

A SOC 2 Type II report is the artifact that answers that question. Type I asks whether controls were designed appropriately at a single point in time. Type II asks whether they actually operated, correctly, across a period of months. It is the difference between a photograph and a film.

// Who did what
  1. 01
    DrataAutomation platform

    Continuous control monitoring and automated evidence collection from cloud infrastructure, identity systems and endpoints.

  2. 02
    AgencyCompliance engineering

    The security and compliance team operating the program day to day: virtual CISO, control implementation, evidence collection and continuous monitoring.

  3. 03
    Zero Day CPAIndependent examiner

    Performed the SOC 2 Type II examination and issued the report. Independence rules mean this can only be a separate firm.

  4. 04
    H2Om.AIPlatform engineering

    Architected, designed, built and maintains the system the controls run inside.

That last row is the one worth dwelling on, because it is where most first examinations are won or lost long before an auditor is engaged.

We were the architect, designer, developer, and maintainer of Rise's entire IP and technology stack, from conception to present.
Nicholas Papillon, H2Om.AI

"First pass, no exceptions" — what that actually means

Here is where we are going to be pedantic on purpose, because precision is the product.

SOC 2 is an attestation, not a certification

There is no SOC 2 certificate. There is no pass or fail grade, and no governing body that stamps approval. What exists is an examination: an independent CPA firm tests your controls against the AICPA Trust Services Criteria and issues a report containing its professional opinion.

"SOC 2 certified" became industry shorthand because certification is a familiar word and attestation is an accounting term. But the shorthand quietly loses the thing that matters, which is that a SOC 2 outcome is not binary. It is a document, and documents can say very different things.

// The distinction

The common shorthand

  • "We are SOC 2 certified."
  • Implies a pass or fail verdict.
  • Implies a certificate exists.
  • Says nothing about scope.
  • Says nothing about findings.

What the report says

  • An examination report containing a CPA firm's professional opinion.
  • Contains an opinion: unqualified, qualified, adverse, or a disclaimer.
  • No certificate is issued. The deliverable is the report itself.
  • Names the exact criteria examined and the observation period.
  • Lists every control tested and every exception found.

An unqualified opinion is not the same as a clean one

This is the part almost nobody outside the audit profession knows, and it is the reason we phrase our claim the way we do.

An unqualified opinion, sometimes called a clean report, means the examiner concluded the controls met the criteria in all material respects. It is the best available opinion. But it does not mean the examiner found nothing. As the CPA firm Linford & Company puts it plainly, it is quite common to have an unqualified opinion with exceptions defined within the report. If compensating controls covered the gap, the opinion can still be unqualified.

So there are two bars, and they are not the same height:

  • An unqualified opinion means nothing found rose to the level of changing the auditor's conclusion.
  • An unqualified opinion with no exceptions noted means the examiner tested the controls in scope and found none that failed.

Rise cleared the second bar, on a first examination. That is the claim, stated at the precision it deserves.

How a first examination comes back clean

Most first examinations do not. The usual pattern is a remediation loop: the examination surfaces control failures, the organization fixes them, and evidence then has to be regathered across a fresh observation window before a report can be issued. That commonly adds months, and it arrives at the worst possible moment, because companies typically start a SOC 2 because a deal already depends on it.

Avoiding that loop comes down to three things, and all three are decided by engineers long before an auditor appears.

  1. Scope is settled before policy is written. The most expensive first-audit mistake is writing policies before deciding what the audit actually covers. Scope determines the systems, the people and the evidence, and every hour spent on documentation outside it is wasted.
  2. Controls are designed into the architecture, not bolted onto it. Access control, encryption, logging, change management and backup are architectural decisions. Retrofitting them into a finished system is what produces exceptions.
  3. The system generates its own evidence. This is the one that decides the outcome. A Type II examination tests whether controls operated continuously across the whole observation window. If evidence is assembled by people after the fact, there will be gaps, because humans miss days. If the system emits evidence automatically, the record is complete by construction.

That third point is why we treat compliance as an engineering concern rather than a documentation exercise. An auditor cannot test a control that left no trace.

What this means if you are buying

If you run technology for a district or charter network

FERPA and SOC 2 answer different questions, and you want both answered. FERPA is the federal law governing the privacy of student education records and what a school may disclose. It sets the obligation. A SOC 2 Type II report is independent evidence that a vendor's security controls actually operated over time. It is how the obligation gets met in practice.

When you request a report, read past the opinion paragraph. Check the observation period, check which trust services criteria were in scope, and read the exceptions section. A vendor with a narrow scope and a clean opinion may have proven considerably less than a vendor with a broad scope and one immaterial exception.

If you are evaluating a partner for defense-adjacent work

The question worth asking is not whether a vendor can name frameworks. It is whether the systems they have already delivered survived contact with an outside party who had every reason to find problems. Procurement decisions and audit opinions are both, in the end, someone independent putting their name to a judgment about your work.

What we are not claiming

Frequently Asked Questions

Is SOC 2 a certification or an attestation?

SOC 2 is an attestation, not a certification. There is no certificate, no pass or fail grade, and no governing body that stamps approval. An independent CPA firm examines your controls against the AICPA Trust Services Criteria and issues a report containing its professional opinion. The phrase "SOC 2 certified" is industry shorthand, but the accurate description is that an organization has received a SOC 2 report, and what matters is what that report says.

What does "no exceptions noted" mean in a SOC 2 Type II report?

An exception is an instance where the examiner tested a control and found that it did not operate as described during the observation period. "No exceptions noted" means the examiner tested the controls in scope and found none that failed. This is a stricter outcome than an unqualified opinion on its own, because a report can carry an unqualified opinion and still list exceptions that were judged not material enough to change that opinion.

What is a SOC 2 remediation loop, and how do you avoid one?

A remediation loop happens when an examination surfaces control failures, the organization fixes them, and evidence must then be regathered across a new observation window before the report can be issued. It commonly adds months. It is avoided by designing controls into the system architecture before the observation window opens, so that the evidence an examiner asks for is generated automatically by the system rather than assembled by people after the fact.

Does an edtech platform need SOC 2 Type II if it already complies with FERPA?

They answer different questions, and most institutional buyers now want both. FERPA is a federal law governing the privacy of student education records and what a school may disclose. SOC 2 Type II is an independent examination of whether the security controls a vendor claims to operate actually operated over a period of time. FERPA sets the obligation; a SOC 2 Type II report is evidence that a vendor can meet it.

Can a software development partner get my product through SOC 2 Type II?

A development partner cannot issue or grant the report, because only an independent CPA firm can do that. What a development partner determines is whether the examination is achievable without a remediation cycle, because access control, logging, encryption, change management and evidence generation are architectural decisions made long before an auditor is engaged. Retrofitting them into a finished system is what turns a first examination into a multi-month remediation loop.

Building something that has to survive an audit?

The controls an examiner tests are architectural decisions, and they are cheapest to make before the first line of code. Our four-week Proof Sprint delivers working, deployable software with the evidence trail already built in.

More from H2Om.AI