When you bring Straight Path into your SQL Server environment, you’re giving our DBAs privileged access to the systems that hold patient records, member accounts, customer data, and the operations your business runs on. We take that seriously, and we’ve had our practices independently examined. This page covers what we’ve done, what’s still in progress, and how your security or compliance team can get what they need from us.
At a glance
| SOC 2 Type I report | Issued September 22, 2026 by Linford & Company LLP, an independent CPA firm. Controls examined as of September 15, 2026. |
| Criteria | Security (the AICPA Trust Services Criteria) |
| System in scope | Managed SQL Server Services, including our monitoring platform and the software we develop |
| SOC 2 Type II | Six-month observation period underway. Report expected April or May of 2027. |
| Going forward | Annual SOC 2 examinations are planned and budgeted. |
| Getting the report | Available to clients and prospective clients on request. |
What our SOC 2 report does and doesn’t tell you
A SOC 2 Type I report is an independent CPA firm’s opinion that, on a specific date, our controls were in place and suitably designed to meet the Security criteria. Think of it as a snapshot. Our Type II report will go further and test whether those controls operated effectively over a six-month period.
SOC 2 is an attestation report, and there’s no such thing as a SOC 2 certification, so you won’t see us call ourselves “SOC 2 certified.” The report doesn’t eliminate risk, and it doesn’t replace your own due diligence. We’d rather you ask us hard questions. If you want the longer story of why we did this and what we learned, read our blog post.
How we protect the access you give us
- We don’t host your databases or store your business data in our environment. Our DBAs work inside yours. Our monitoring collects performance and health telemetry which is encrypted at rest from the moment it is collected and then in transit through every step of our processes.
- Each DBA uses an individually named account in client environments when requested, though some clients allow for shared account access following our process and controls.
- Client credentials are stored in a password vault with multi-factor authentication enforced and regular audits of our vaults.
- Where we use remote access tools, we use a tool which is compliant with all security frameworks our clients are concerned with, and each account forces multi-factor authentication, and access is logged.
- Multi-factor authentication, background checks, managed company devices, and active security monitoring through our managed security partner, Mainstay Technologies.
- Security training for every team member, with evidence kept for our auditors.
- Formal, repeatable reviews of the vendors we rely on.
- Incident response plans that we test through tabletop exercises.
About the access we need
We’d rather be upfront about this. Our DBAs need sysadmin on your SQL Server instances and local admin on the servers, for both DBA work and our monitoring. If your organization uses a privileged access management (PAM) tool to grant that access on demand, we’re glad to work within it, and several of our clients do. We do not need this access all day everyday and are fine to work with least privilege so long as we have the ability to check out the secure credentials on demand.
Security is a shared job
Our SOC 2 report lists complementary user entity controls, which are the responsibilities our clients handle on their side of the relationship. We’ll walk your team through them and help where we can.
Security For Healthcare and credit unions
- Healthcare: we review and sign our clients’ Business Associate Agreements (BAAs).
- Credit unions: our SOC 2 report and policies are there to support your third-party due diligence and your examiners’ questions.
Frequently asked questions
Does Straight Path have a SOC 2 report?
Yes. Linford & Company LLP, an independent CPA firm, issued Straight Path’s SOC 2 Type I report on September 22, 2026. It covers the Security criteria for our Managed SQL Server Services as of September 15, 2026. Our six-month SOC 2 Type II examination is underway.
Is Straight Path SOC 2 certified?
There’s no such thing as a SOC 2 certification. SOC 2 is an attestation report issued by an independent CPA firm. Straight Path has a SOC 2 Type I report and is in the observation period for its SOC 2 Type II report.
What’s the difference between SOC 2 Type I and Type II?
A Type I report looks at whether controls are in place and suitably designed on a single date. A Type II report tests whether those controls operated effectively over a period of time. Straight Path’s Type II observation period is six months for the initial Type II, and we will perform an audit annually after that.
Can we see Straight Path’s SOC 2 report?
Yes. Clients and prospective clients protected by a mutual NDA may request a copy.
Does Straight Path store our data?
Straight Path doesn’t host client databases or store client business data in its own environment. Our DBAs work inside your environment, and our monitoring collects performance and health telemetry.
What access do Straight Path’s DBAs need?
Our DBAs need sysadmin on your SQL Server instances and local admin on the servers, for both DBA work and monitoring. We’re glad to work within a privileged access management (PAM) tool if your organization uses one to grant that access on demand.
Will Straight Path sign a Business Associate Agreement (BAA)?
Yes. Straight Path reviews and signs its healthcare clients’ Business Associate Agreements.
How often is Straight Path audited?
After our first SOC 2 Type II report, we will submit to be examined every year so there’s no gap in coverage.
Questions from your security or compliance team?
Send them our way. We’ll answer them straight, and if we’re not the right fit, we’ll tell you that too. Contact us.