In August we started our SOC 2 program with Sprinto, and at the end of that month our HIPAA program was complete. Today the second half is done. Cync has completed its SOC 2 examination, the independent review of how a service organization protects the systems and data its customers trust it with.
What was examined
SOC 2 is a framework from the AICPA. A licensed CPA firm, independent of us, examines the controls a company runs and reports on them. For Cync that meant the safeguards practices already rely on: access limited by role, a second factor on every account, encryption in transit and at rest, a reviewed path for every change to the platform, an activity record of every sign-in and change, and a plan for the day something goes wrong.
None of those were built for the examination. They are how Cync was engineered from the start, and continuous monitoring through Sprinto had been collecting the evidence every day since August. The examination tested what was already there.
What this means for your practice
Before a practice approves new software, someone on the IT or compliance side usually asks for a SOC 2 report. Now you can hand them one. Paired with a business associate agreement that comes standard with every practice, it answers most of a vendor security review before the questionnaire arrives, so getting started takes days instead of a quarter.
It does not stop here
A SOC 2 report describes a period of time, so it has to be earned again. Our controls stay under continuous monitoring, drift is caught the same day rather than at the next review, and we will be examined again on a regular cycle so the report your reviewers read is always current.
Request the report
The Cync Trust Center at trustcenter.cyncmd.com publishes our compliance posture in real time, and it is where your reviewers can request the SOC 2 report itself. If they want evidence rather than assurances, send them there.