We received our official and final SOC 2 Type I report from Linford & Company, an independent CPA firm, covering our Managed SQL Server Services as of September 15, 2026 today. I’m proud of it. I’m also a little wary of how these announcements usually go, because I’ve read a lot of vendor press releases that make a SOC 2 report sound like a force field. So I want to walk through what we actually did, what the report says, what it doesn’t say, and why we’re already on the hook for the next one.
No client asked us to do this
That’s the first thing I want people to know. Nobody made us. We’ve been doing this since 2011 and we’ve passed plenty of vendor questionnaires without a SOC report. Maybe the desire to do a couple less vendor questionnaires motivated me, but then I learned that we’ll still get them – but I also learned that our managed service provider for IT and MS365 and security will also fill those out for me. So that’s still a win.
When you hire us, you’re handing us the keys to the kingdom. Our DBAs get privileged access to SQL Servers that hold patient records, member accounts, customer orders, payroll (the stuff that keeps your business running and keeps people’s lives in order). We help clients get through audits and security reviews all the time. It felt a little hypocritical to keep asking you to trust our answers when we’d never had anyone outside the company check them and keep watching.
What we actually did
We’re a 22-person company. Hiring a full-time CISO didn’t make sense for our size, and the “buy a compliance platform and click through the checklist” route didn’t give me what I wanted, which was someone who knew our business telling me where we were weak. I don’t want a rubber stamp – this was not a cheap expense – and it is a new ongoing line item – the managed security services and the annual audit we’ll have to keep our SOC2 Type II up once we (hopefully) achieve that in 6 months is an expense. The extra time to do some things, the process, the forced patching reboots. It’s all a cost – but it’s worth it.
So we leaned on Mainstay Technologies, who already run our managed IT and security monitoring. Erin Mealey guided the SOC 2 work start to finish, and internally Evan Corbett (our COO) drove the follow-through while Buck Woody brought a lot of hard-won data security and incident response experience from his roles at Microsoft for the past nearly 20 years.
The work itself was a lot of turning things we already did into things we could prove we do: documenting controls, formalizing policies, running every vendor through the same review, security training with evidence behind it, and testing our response plans. We also pulled our monitoring platform, Skopos, and the software we write into scope, because that’s part of how we serve clients and leaving it out would have made the report look tidier than reality.
I expected more misery than we got. The part I figured would be pure box-checking was the disaster tabletop exercises. It wasn’t. Walking through those scenarios surfaced real risks, and we changed some of our approaches and policies because of them. Turns out we had some homework. I’d rather find that out in a conference room than at 2 a.m. on a client’s server.
What a SOC 2 Type I actually is
SOC 2 is an examination framework from the AICPA. An independent CPA firm looks at a company’s description of its system and its controls against a set of criteria. We were examined against the Security criteria, which is the required baseline for every SOC 2.
A Type I is a snapshot only. It says that on a specific date, our controls were in place and suitably designed to meet those criteria.
I spent years as a firefighter and EMT, so here’s how I think about it. A Type I is the inspector walking the building and confirming the smoke detectors are installed, wired correctly, and in the right rooms. A Type II is the inspector coming back and checking the logs to see that they were tested every month and actually went off when there was smoke, and the folks followed the evacuation plan months later.
What it doesn’t mean
This is the part I care about most, because transparency matters, it’s the whole point behind the Buying DBA Services guide posts I’ve been sharing. Don’t let our “SOC2 Achieved!” woo you into letting your guard down. Even when we hopefully pass our Type II audit.
- It isn’t a certification. There’s no such thing as being “SOC 2 certified,” even though you’ll see vendors say it everywhere. It’s an attestation report from a CPA firm. We’ll try hard not to call it a certification, and if you catch us doing it, tell us.
- It doesn’t prove our controls worked over time. That’s what Type II is for, and we’re not there yet.
- It doesn’t mean nothing bad can happen. No report eliminates risk. Anyone who tells you otherwise is selling something.
- It doesn’t cover your servers. The report is about how Straight Path runs. We don’t host your data in our environment. The security of your SQL Servers is still a shared job, and the report even lists things clients are expected to do on their side (auditors call these complementary user entity controls, apparently). We’ll help you with those, but they’re yours. We think the time is right for you to have a PAM tool, as much as the DBA in me cringes typing it, but that’s your decision and a CUEC suggests it – we can tell you how others have done it but this is up to your security team.
- It doesn’t replace your due diligence. It gives you better evidence to work with. You should still ask us hard questions, ask our competitors hard questions, get to know the team, and decide if we’re the right fit.
- It doesn’t mean we changed who we are. We’re still the same bunch of SQL Server geeks. We just have more evidence behind the promise and more documentation, process and checkboxes for the team to follow behind the scenes.
Why it’s still worth it
The SOC 2 (or ISO27001) journey can absolutely be an expensive paperwork exercise that makes a company look secure without making it more secure. I’ve seen that happen.
What made it worth it for us came from a few places:
We found our unknown unknowns. We already had solid basics in place (MFA, background checks, managed devices, active monitoring, phishing tests, perimeter security, see something say something policies, etc.). The value was in the questions we didn’t know to ask ourselves, and the tabletop drills were the best example. Or pushing the same questions and process on our own vendors was a good takeaway – rigidity up and down.
The team’s defaults changed. I’ve watched people make more secure-by-default decisions without anyone prompting them. This team was already mature and security already mattered here, but now I can see it in how everyday choices get made.
Rules for everyone make life easier. When we were five people, a lot of how we worked lived in my head and a couple of other heads. Having clear policies that apply to everyone, me included, has made things simpler than the early days.
Your vendor reviews get easier. If you’re a credit union, you’re expected to do real due diligence on third-party providers and your examiners will ask about it. If you’re in healthcare, you’re asking vendors how they protect PHI. Now we can hand you independent evidence instead of a well-written questionnaire answer alone.
The monitoring already proved itself once. Before the formal SOC 2 work even started, some activity on my laptop tripped an automated response falsely. My laptop got isolated, my account got locked, and Mainstay’s security team called me. It turned out to be harmless. I was annoyed for about an hour, and then really glad, because that’s exactly what I want to happen when something looks wrong.
Why we’re already in the Type II phase
A Type I tells you we designed things well on one day. That’s a real milestone, but it’s a starting line. The question anyone serious about vendor risk will ask next is “did you keep doing it?” Even “are you going to keep doing it diligently forever?”
Yeah we are –> Our six-month Type II observation period with Linford is now underway or about to be (not officially sure how it works – but it’s next and we are waiting 6 months to have enough of a period to catch us doing something wrong, and move it to 2027 so we can go annual after that.) During that window we have to operate the controls we described, keep the evidence, and then let the auditors test random samples across the whole period. If a control slips, the report will say so, we can’t do anything about it. That’s the point of it.
Why annual audits are in our budget
This wasn’t a one-time project, and we’ve budgeted it that way. After the Type II, we plan to be examined every year.
A few reasons:
- Reports age. A report that covers a period that ended a year ago tells you less and less every month. Auditors themselves recommend producing them annually so there’s no gap between reporting periods.
- Your reviews are annual. Most of our regulated clients re-review their vendors every year. We should have something current to hand them.
- Discipline decays without an outside deadline. I know myself alllllll too well. Good habits hold up a lot better when someone independent is coming back to check. Outside accountability helps. Plus it makes the process the bad guy, not me with all our process and procedures and security.
- It matches how we already do business. We don’t lock clients into long-term contracts, because we think we should have to earn your business every quarter. It would be a little strange to then ask you to trust a snapshot from years ago.
It’s a line item now, like insurance and training. I’m okay with that.
What this means if you work with us (or are thinking about it)
If you’re a client and your compliance team wants to see the report, reach out to us and we’ll get it to you, you’ll see it on your next vendor questionnaire round if you are one of the many who send the links to them. If you’re evaluating us, ask for it, and ask us anything else too. What we train on, what happens when something goes wrong, what our policies actually say. Those are fair questions, and you should ask them of every vendor who touches your data.
We really care about the data we look after. Behind every row in those tables are people, families, customers, and livelihoods. This report is one piece of evidence that we mean it. The rest we’ll keep earning the same way we always have – earning the next renewal by proving ourselves to be a part of your team, not just another vendor.
Have a SQL Server environment you want an honest conversation about? Let’s talk.