Birdview has completed its 2026 AICPA SOC 2 Type II audit, conducted by independent CPA firm Prescient Assurance, LLC. The audit tests whether Birdview’s security controls are operating effectively and gives customers current, independent evidence for vendor security reviews. It’s Birdview’s 3rd consecutive annual SOC 2 Type II audit.
What did the 2026 SOC 2 Type II audit cover?
The 2026 audit assessed Birdview’s controls against the AICPA Trust Services Criteria in scope. A Type II audit checks both the design of each control and whether it actually worked throughout the review period, using sampled evidence.
In practice, the auditor reviewed evidence for controls such as access provisioning and removal, change management, vulnerability management, backup and recovery, incident response, and vendor oversight. These are the controls that protect the project, time, and financial data professional services teams store in Birdview PSA.
Why does Birdview repeat the SOC 2 audit every year?
A SOC 2 Type II report covers a fixed past period, so its value to a buyer drops as that period ages. In the vendor security reviews Birdview completes for customers, procurement and IT teams usually ask for a report issued within the last 12 months.
Annual renewal also changes how security work happens day to day. Birdview monitors its controls and collects evidence continuously across a 12-month window, the cadence Prescient Assurance recommends for renewal audits. Security becomes a routine operating process rather than a once-a-year project.
The practical difference shows up in vendor reviews. A buyer comparing PSA vendors can see that Birdview’s controls held up over [X] consecutive months, not only on the day an auditor visited. That is the core difference between a Type II report and a Type I report, which only checks control design at a single point in time.
What does the 2026 SOC 2 report mean for Birdview customers?
For customers, the 2026 report means faster, simpler vendor security reviews. Instead of answering hundreds of questionnaire items from scratch, a security team can review an independent auditor’s opinion and the tested control list.
This matters most for the organizations that rely on Birdview PSA for sensitive delivery data. Healthcare providers, financial institutions, government agencies, and IT consulting firms often need SOC 2 evidence before a contract can be signed or renewed.
The SOC 2 report sits alongside Birdview’s other security and hosting options:
- Data residency: Microsoft Azure hosting in Canadian and US data centers. See the Canadian data residency guide.
- Identity and access: single sign-on with Microsoft Entra ID.
- Deployment choice: on-premise deployment for organizations that cannot use cloud hosting.
How can customers request Birdview’s SOC 2 Type II report?
Customers and prospects can request the full 2026 report through the Birdview Trust Center. SOC 2 Type II is a restricted-use report, so Birdview shares it only under a signed non-disclosure agreement (NDA).
The request process usually looks like this:
- Submit a request through the Trust Center or ask your Birdview account manager.
- Sign Birdview’s mutual NDA, or send your organization’s NDA for review.
- Receive the full report, typically within 5 business days of a signed NDA.
If your team is mid-evaluation, ask for the report early. Security review is often the longest step in a PSA purchase, and starting it in parallel with a trial can save several weeks.
FAQ
Is SOC 2 a certification? SOC 2 is technically an attestation, not a certification. An independent CPA firm issues an opinion on whether a company’s controls meet the AICPA Trust Services Criteria. There is no pass certificate. Instead, buyers read the auditor’s report, including the tested controls and any exceptions, and decide whether the vendor meets their own risk requirements.
What is the difference between SOC 2 Type I and Type II? A SOC 2 Type I report checks whether controls are designed correctly at a single point in time. A Type II report tests whether those controls actually operated effectively over a review period, usually 6 to 12 months. Most enterprise and public-sector buyers ask for Type II because it shows sustained performance.
How long is a SOC 2 Type II report valid? A SOC 2 report has no formal expiry date, but buyers treat it as current for about 12 months after the review period ends. That is why Birdview renews its audit every year. If you hold an older Birdview report, request the 2026 version before your next vendor review.
Can I share Birdview’s SOC 2 report with my auditors or clients? The report is restricted-use and is provided under NDA. You can usually share it with your own auditors and internal security reviewers covered by that NDA. To pass it to your clients or other third parties, contact Birdview first so the right agreement is in place.