Rōvn · Investor Room
AI agent: checking…
All sections
Compliance & Security

SOC 2 Type II Plan

Current truthRōvn master canon generation 8 · effective 2026-07-21. Earlier dated diligence documents are historical snapshots, not current deployment proof.Ask the canon-grounded agent →
AI Diligence Console

SOC 2 Type II Plan

Reviewed: 2026-07-22 · Canon: generation 8, effective 2026-07-21

TL;DR: Rōvn is on a documented SOC 2 Type II trajectory. The observation window opens Q3 2026 and the Type II report is targeted for Q3 2027, after the 12-month observation period closes. Scope: Security, Availability, Confidentiality, Processing Integrity, Privacy. We are not SOC 2 certified, we do not claim an interim Type I attestation, and program status is stated only with current evidence. AI operates the workflow. Source systems prove the facts. Humans make every regulated decision.


1. Why SOC 2

SOC 2 is the trust posture procurement teams ask for at most healthcare buyers above the smallest tier. Without it, deals stall at General Counsel review and CIO security review. HIPAA obligations exist separately; SOC 2 is the procurement-language attestation that lets the review pass. Combined with the HIPAA-aligned, BAA available posture (06.2), it is the evidence pack a buyer's security team actually processes.

We do not represent SOC 2 certification until the audit completes and the report is issued. Current state: program in progress on a documented trajectory.


2. Trajectory

Phase 1: control implementation (through Q3 2026)

  • Trust Services Criteria mapped to specific Rōvn controls on the Google Cloud spine.
  • Continuous-evidence tooling (Drata is the selected platform) collects control evidence; program status claims always require the current evidence export, not a remembered status.
  • Evidence sources include cloud audit logs, repository branch protection, access reviews, and deployment receipts.

Phase 2: Type II observation window (Q3 2026 through Q3 2027)

  • Observation period: 12 months of controls operating effectively.
  • Scope: Security, Availability, Confidentiality, Processing Integrity, Privacy.
  • Auditor: an independent CPA firm; final selection is stated only when the engagement letter is on file.

Phase 3: Type II report (target Q3 2027)

  • Deliverable: SOC 2 Type II attestation report, distributed to customers and procurement teams as part of the standard evidence pack.
  • After the first report, annual recertification continues with rolling 12-month observation periods.

3. Trust Services Criteria scope

TSCCoverage
Security (Common Criteria)Required for every SOC 2 report. Access controls, change management, risk management, system operations, incident response.
AvailabilityUptime, capacity, disaster recovery, business continuity.
ConfidentialityProtection of confidential data: credential metadata, source receipts, audit artifacts.
Processing IntegrityProcessing is complete, valid, accurate, timely, authorized. Covers audit-chain integrity and deterministic policy evaluation.
PrivacyPersonal information handled per notice. Covers consent management and worker data control.

Processing Integrity and Privacy in scope directly support the AI doctrine claim and the worker-controlled Passport claim, respectively.


4. Control framework (Common Criteria mapping)

CCControl areaRōvn implementation direction
CC1Control environmentNamed security owner; written security policy
CC2Communication and informationPolicy distribution; documented vendor management
CC3Risk assessmentAnnual plus ad-hoc risk assessment; tracked register
CC4Monitoring activitiesCloud monitoring, error tracking, alerting with escalation runbook
CC5Control activitiesCode review, branch protection, deployment approval workflow
CC6Logical and physical accessDefault-deny access, least-privilege service identities, cloud physical safeguards under provider agreements
CC7System operationsChange management via reviewed pull requests and CI gates
CC8Change managementProduction changes through reviewed PRs with deployment receipts
CC9Risk mitigationBackup and restore procedures, incident drills; tested before production real-data use

5. Honest build state

What is true today

  • Control framework mapped to the Trust Services Criteria.
  • The deployed environment is synthetic-data-only, which bounds the audit surface during the build-out.
  • Program dates: observation window opening Q3 2026, report target Q3 2027.

What we do not claim

  • SOC 2 certified. No audit report has been issued.
  • Type I attested. An interim Type I attestation is not part of the standard claim.
  • Specific control counts. Control counts vary by audit firm and category. We do not weaponize a number like "147 of 152 controls"; specific counts belong in the issued report.
  • Pentest report available. External pentest is a scheduled target (Q4 2026).

The discipline of saying "in progress" rather than "certified" is what wins procurement long-term. Hospital General Counsels trust honesty more than they trust marketing.


6. The investor reading

  • Industry-standard timeline. The 12-month Type II observation window is the industry norm and cannot be compressed. That is exactly why the program starts now rather than after the first enterprise deal needs it.
  • Right scope. All five Trust Services Criteria, matching what enterprise customers actually request.
  • Compounding. Once the first report issues, each subsequent audit cycle is incremental cost, and the compliance posture becomes a durable asset that supports the Operator and Platform tiers.

End of SOC 2 plan.

Ask the AI agent about this section, the raise, compliance posture, or any cross-document question. Grounded in Rōvn canon generation 8, with on-page source citations.

Investor questions run through Google Cloud Vertex AI and are constrained to the hash-pinned Rōvn generation 8 canon. No PHI belongs in this room or its prompts.