Search all 478 artefacts by title, document ID or content.
Statement | Family 4, Assurance & Evidence
Edsol Edtech Pvt. Ltd. has no SOC 2 report of any type. No examination has been commenced and no CPA firm has been engaged. A note on vocabulary, because it is routinely got wrong. SOC 2 produces a report containing a practitioner's opinion. It does not produce a certificate, and no organisation is "SOC 2 certified".
STM-GL-012 v1.0.0, Last Modified On 31 July 2026, Tier: Public
Edsol Edtech Pvt. Ltd.has no SOC 2 report of any type. No examination has been commenced and no CPA firm has been engaged.A note on vocabulary, because it is routinely got wrong. SOC 2 produces a report containing a practitioner's opinion. It does not produce a certificate, and no organisation is "SOC 2 certified".
Pensieve Labswill not use that phrase and a hospital should treat any vendor that does as having not read its own report.
To state plainly whether Pensieve Labs intends to obtain a SOC 2 report, when, in what order relative
to ISO/IEC 27001, and why that order was chosen.
| Field | Value |
|---|---|
| SOC 2 Type I | Not held. Not commenced |
| SOC 2 Type II | Not held. Not commenced |
| SOC 3 | Not held. Not commenced |
| SOC 1 / ISAE 3402 | Not held and not planned (see Section 5) |
| CPA firm engaged | Roadmap soc2 cpa firm |
| Trust Services Criteria intended | Security (mandatory), Availability, Confidentiality. Processing Integrity and Privacy are not in the intended initial scope (see Section 3) |
| TSC control mapping | Published (CHK-GL-029) |
| Type I target | Roadmap soc2 type1 target |
| Type II observation window | Roadmap soc2 type2 window |
| Type II report target | Roadmap soc2 type2 target |
| SOC 3 target | Roadmap soc3 target |
| Programme owner | Roadmap soc2 owner |
Pensieve Labs will obtain ISO/IEC 27001:2022 first and SOC 2 second. The reasoning is stated so
that a reviewer can disagree with it on the record:
Pensieve Labs sells into ask for ISO, not SOC. Indian hospital chains, Danish and
Norwegian regional procurement, UAE group hospitals and Australian private groups all treat ISO/IEC
27001 as the reference credential. SOC 2 carries real weight with hospitals owned by or linked to a
United States parent, and close to none with an owner-operated Indian hospital.The consequence for a hospital evaluating Pensieve Labs today: if a SOC 2 report is a hard
requirement of your procurement, say so early. It is not on the near-term path, and Pensieve Labs
would rather tell you that in week one than in week six.
| Decision | Position |
|---|---|
| Security (Common Criteria) | In scope. Mandatory in every SOC 2 examination |
| Availability | In scope. Pensieve Labs makes availability commitments in SLA-GL-001 and a report that excludes availability would not test them |
| Confidentiality | In scope. Directly relevant to a processor handling hospital records |
| Processing Integrity | Out of the initial scope. It is the criterion most often scoped in for marketing reasons and most often meaningless. Pensieve Labs will add it only if a customer's diligence genuinely requires it, and will say so rather than adding it for the badge |
| Privacy | Out of the initial scope. The privacy position is already addressed by DPA-GL-001, REG-GL-206, CHK-GL-024, CHK-GL-033 and, in the ISO programme, by ISO/IEC 27018 as an extension. Duplicating it in a SOC 2 Privacy criterion adds cost without adding assurance |
| Type II window length | Three months for the first report, moving to a twelve-month annual cadence. Three months is accepted for a first report and there is no way to compress the window. The window is the point of the report |
| SOC 3 | Bought in the same engagement letter as the Type II, never as an afterthought. SOC 3 is a general-use report derived from the same examination and is the only member of the SOC family that can be published openly with no NDA. For a Trust Center biased toward open publication, it removes an entire NDA round trip, typically several days of deal clock |
| # | Milestone | Owner | Target | Status |
|---|---|---|---|---|
| 1 | Trust Services Criteria control mapping published | Roadmap soc2 owner |
Complete | Done: CHK-GL-029 |
| 2 | ISO/IEC 27001 certificate obtained | Roadmap iso27001 owner |
Roadmap iso27001 target |
Not started (STM-GL-011) |
| 3 | US-licensed CPA firm engaged, with SOC 3 written into the engagement letter | Roadmap soc2 owner |
Roadmap soc2 engagement target |
Not started |
| 4 | System description drafted | Roadmap soc2 owner |
Roadmap soc2 type1 target |
Not started |
| 5 | Readiness assessment and remediation | Roadmap soc2 cpa firm |
Roadmap soc2 type1 target |
Not started |
| 6 | Type I examination: suitability of design at a point in time | Roadmap soc2 cpa firm |
Roadmap soc2 type1 target |
Not started |
| 7 | Type II observation window opens the day the Type I is signed | Roadmap soc2 owner |
Roadmap soc2 type2 window |
Not started |
| 8 | Type II report issued | Roadmap soc2 cpa firm |
Roadmap soc2 type2 target |
Not started |
| 9 | SOC 3 issued and published openly | Roadmap soc2 cpa firm |
Roadmap soc3 target |
Not started |
Milestone 7 is a scheduling discipline, not a formality. The observation window is the single longest
element of the SOC 2 timeline and it is the only one that runs without effort. It starts the day the Type I
is signed so that the clock runs while Pensieve Labs sells.
SOC 1 (SSAE 18 / ISAE 3402) is relevant where a vendor's platform forms part of a customer's financial
reporting control environment. Pensieve includes revenue-cycle, billing and claims functions,
which is exactly the class of system a listed company's external auditor scopes in, so the question is not
absurd.
Position: not pursued today. Pensieve Labs's near-term customers are privately held hospitals whose
statutory audit does not depend on the platform in that way. This will be revisited if
Edsol Edtech Pvt. Ltd. wins a listed or publicly funded customer whose auditor requires it, and the
decision will be recorded here rather than in a conversation.
Pensieve Labs will never buy, and why it belongs in this documentHITRUST: no tier, ever, unless a United States customer appears. HITRUST e1, i1 and r2 are artefacts of
the United States health-plan and health-system market, driven by HIPAA business-associate and payer
requirements. No Indian, Australian, Danish, Norwegian or Emirati hospital procurement process asks for it,
and the mid-tier alone would cost more than Pensieve Labs's entire certification programme through the
SOC 2 Type II while unlocking nothing.
It appears in this document because a roadmap that lists only what a company intends to buy is less
informative than one that also states what it has decided not to. WPR-GL-005 Section 6.4 carries the full list.
Pensieve Labs in week one. It is not on the
near-term path.CHK-GL-029. The Trust Services Criteria mapping is published and
testable against WPR-GL-001 today, which is more than most SOC 2 reports allow a buyer to do: a Type
II report is NDA-gated and its control matrix is rarely read.Pensieve Labs
has already committed to buying it in the same engagement letter.Re-issued within 5 business days of any milestone completing, and re-dated with a stated reason if a
target slips. Previous target dates remain visible in the change history below. Reviewed quarterly against
STM-GL-011 and WPR-GL-005.
Edsol Edtech Pvt. Ltd. holds no SOC 2 Type I report, no SOC 2 Type II report and no SOC 3
report. The dates above are targets, not commitments, unless separately contracted.
| Signature | ______________________________ |
| Name | [TO BE SUPPLIED] |
| Designation | Director |
| For | Edsol Edtech Pvt. Ltd. |
| Date | 31 July 2026 |
| Version | Date | Author | Type I target carried | Type II target carried | Summary |
|---|---|---|---|---|---|
| 1.0.0 | 31 July 2026 |
Security | Roadmap soc2 type1 target |
Roadmap soc2 type2 target |
First issue. |