Are you SOC 2 Type II compliant?
Not yet. Type I is targeted for issuance in Q4 2026; Type II, which requires an observation period, targets Q2 2027. The audit firm and readiness platform are being selected, and we share the readiness roadmap and the current auditor relationship under NDA. One thing we want to say plainly rather than let you infer it: self-hosting does not make a SOC 2 on Sparcle irrelevant. It changes which scope matters. There is no Sparcle-hosted store of your data for an auditor to examine, but we do write, review, build, sign and ship the software that runs inside your perimeter, and we operate the update channel it trusts. A compromised build, a stolen signing key, an unpatched dependency or a careless support workflow are all real routes into your environment, and those are exactly the controls a Type II tests over time. So treat the engineering and release controls described elsewhere on this page as the interim answer, not as a reason the audit does not apply.