Search all 478 artefacts by title, document ID or content.
Statement | Family 4, Assurance & Evidence
Edsol Edtech Pvt. Ltd. has no SOC 2 report of any type. No examination has been commenced and no CPA firm has been engaged. A note on vocabulary, because it is routinely got wrong. SOC 2 produces a report containing a practitioner's opinion. It does not produce a certificate, and no organisation is "SOC 2 certified".
This document is the source of truth for: soc2-target-date, marketing:/trust/soc-2
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
STM-GL-012 v1.0.0, Last Modified On 31 July 2026, Tier: Public
Edsol Edtech Pvt. Ltd.has no SOC 2 report of any type. No examination has been commenced and no CPA firm has been engaged.A note on vocabulary, because it is routinely got wrong. SOC 2 produces a report containing a practitioner's opinion. It does not produce a certificate, and no organisation is "SOC 2 certified".
Pensieve Labswill not use that phrase and a hospital should treat any vendor that does as having not read its own report.
To state plainly whether Pensieve Labs intends to obtain a SOC 2 report, when, in what order relative
to ISO/IEC 27001, and why that order was chosen.
| Field | Value |
|---|---|
| SOC 2 Type I | Not held. Not commenced |
| SOC 2 Type II | Not held. Not commenced |
| SOC 3 | Not held. Not commenced |
| SOC 1 / ISAE 3402 | Not held and not planned (see Section 5) |
| CPA firm engaged | Roadmap soc2 cpa firm |
| Trust Services Criteria intended | Security (mandatory), Availability, Confidentiality. Processing Integrity and Privacy are not in the intended initial scope (see Section 3) |
| TSC control mapping | Published (CHK-GL-029) |
| Type I target | Roadmap soc2 type1 target |
| Type II observation window | Roadmap soc2 type2 window |
| Type II report target | Roadmap soc2 type2 target |
| SOC 3 target | Roadmap soc3 target |
| Programme owner | Roadmap soc2 owner |
Pensieve Labs will obtain ISO/IEC 27001:2022 first and SOC 2 second. The reasoning is stated so
that a reviewer can disagree with it on the record:
Pensieve Labs sells into ask for ISO, not SOC. Indian hospital chains, Danish and
Norwegian regional procurement, UAE group hospitals and Australian private groups all treat ISO/IEC
27001 as the reference credential. SOC 2 carries real weight with hospitals owned by or linked to a
United States parent, and close to none with an owner-operated Indian hospital.The consequence for a hospital evaluating Pensieve Labs today: if a SOC 2 report is a hard
requirement of your procurement, say so early. It is not on the near-term path, and Pensieve Labs
would rather tell you that in week one than in week six.
| Decision | Position |
|---|---|
| Security (Common Criteria) | In scope. Mandatory in every SOC 2 examination |
| Availability | In scope. Pensieve Labs makes availability commitments in SLA-GL-001 and a report that excludes availability would not test them |
| Confidentiality | In scope. Directly relevant to a processor handling hospital records |
| Processing Integrity | Out of the initial scope. It is the criterion most often scoped in for marketing reasons and most often meaningless. Pensieve Labs will add it only if a customer's diligence genuinely requires it, and will say so rather than adding it for the badge |
| Privacy | Out of the initial scope. The privacy position is already addressed by DPA-GL-001, REG-GL-206, CHK-GL-024, CHK-GL-033 and, in the ISO programme, by ISO/IEC 27018 as an extension. Duplicating it in a SOC 2 Privacy criterion adds cost without adding assurance |
| Type II window length | Three months for the first report, moving to a twelve-month annual cadence. Three months is accepted for a first report and there is no way to compress the window. The window is the point of the report |
| SOC 3 | Bought in the same engagement letter as the Type II, never as an afterthought. SOC 3 is a general-use report derived from the same examination and is the only member of the SOC family that can be published openly with no NDA. For a Trust Center biased toward open publication, it removes an entire NDA round trip, typically several days of deal clock |
| # | Milestone | Owner | Target | Status |
|---|---|---|---|---|
| 1 | Trust Services Criteria control mapping published | Roadmap soc2 owner |
Complete | Done: CHK-GL-029 |
| 2 | ISO/IEC 27001 certificate obtained | Roadmap iso27001 owner |
Roadmap iso27001 target |
Not started (STM-GL-011) |
| 3 | US-licensed CPA firm engaged, with SOC 3 written into the engagement letter | Roadmap soc2 owner |
Roadmap soc2 engagement target |
Not started |
| 4 | System description drafted | Roadmap soc2 owner |
Roadmap soc2 type1 target |
Not started |
| 5 | Readiness assessment and remediation | Roadmap soc2 cpa firm |
Roadmap soc2 type1 target |
Not started |
| 6 | Type I examination: suitability of design at a point in time | Roadmap soc2 cpa firm |
Roadmap soc2 type1 target |
Not started |
| 7 | Type II observation window opens the day the Type I is signed | Roadmap soc2 owner |
Roadmap soc2 type2 window |
Not started |
| 8 | Type II report issued | Roadmap soc2 cpa firm |
Roadmap soc2 type2 target |
Not started |
| 9 | SOC 3 issued and published openly | Roadmap soc2 cpa firm |
Roadmap soc3 target |
Not started |
Milestone 7 is a scheduling discipline, not a formality. The observation window is the single longest
element of the SOC 2 timeline and it is the only one that runs without effort. It starts the day the Type I
is signed so that the clock runs while Pensieve Labs sells.
SOC 1 (SSAE 18 / ISAE 3402) is relevant where a vendor's platform forms part of a customer's financial
reporting control environment. Pensieve includes revenue-cycle, billing and claims functions,
which is exactly the class of system a listed company's external auditor scopes in, so the question is not
absurd.
Position: not pursued today. Pensieve Labs's near-term customers are privately held hospitals whose
statutory audit does not depend on the platform in that way. This will be revisited if
Edsol Edtech Pvt. Ltd. wins a listed or publicly funded customer whose auditor requires it, and the
decision will be recorded here rather than in a conversation.
Pensieve Labs will never buy, and why it belongs in this documentHITRUST: no tier, ever, unless a United States customer appears. HITRUST e1, i1 and r2 are artefacts of
the United States health-plan and health-system market, driven by HIPAA business-associate and payer
requirements. No Indian, Australian, Danish, Norwegian or Emirati hospital procurement process asks for it,
and the mid-tier alone would cost more than Pensieve Labs's entire certification programme through the
SOC 2 Type II while unlocking nothing.
It appears in this document because a roadmap that lists only what a company intends to buy is less
informative than one that also states what it has decided not to. WPR-GL-005 Section 6.4 carries the full list.
Pensieve Labs in week one. It is not on the
near-term path.CHK-GL-029. The Trust Services Criteria mapping is published and
testable against WPR-GL-001 today, which is more than most SOC 2 reports allow a buyer to do: a Type
II report is NDA-gated and its control matrix is rarely read.Pensieve Labs
has already committed to buying it in the same engagement letter.Re-issued within 5 business days of any milestone completing, and re-dated with a stated reason if a
target slips. Previous target dates remain visible in the change history below. Reviewed quarterly against
STM-GL-011 and WPR-GL-005.
Edsol Edtech Pvt. Ltd. holds no SOC 2 Type I report, no SOC 2 Type II report and no SOC 3
report. The dates above are targets, not commitments, unless separately contracted.
| Signature | ______________________________ |
| Name | [TO BE SUPPLIED] |
| Designation | Director |
| For | Edsol Edtech Pvt. Ltd. |
| Date | 31 July 2026 |
| Version | Date | Author | Type I target carried | Type II target carried | Summary |
|---|---|---|---|---|---|
| 1.0.0 | 31 July 2026 |
Security | Roadmap soc2 type1 target |
Roadmap soc2 type2 target |
First issue. |