Vendor SOC 2 reports for third-party assessment
Last updated: September 16, 2025
When conducting security assessments or compliance audits, you may need to obtain SOC 2 reports and other documents from third-party vendors that your application uses.
Accessing Mycroft's SOC 2 report
You can access our SOC 2 report through our trust portal at https://app.mycroft.io/trust/mycroft. This link can be shared directly with stakeholders who need to review our compliance documentation.
Authentication and SSO Support
When completing security questionnaires, please note Mycroft's current authentication capabilities:
OIDC (OpenID Connect) - Fully supported
Microsoft Entra ID - Supported
SAML - Not currently supported
Requesting SOC 2 reports
You may be asked to provide a SOC 2 report or similar documentation regarding a third-party vendor to achieve your compliance goal. The Mycroft Customer Success team can work with you to ensure these are not missed during readiness, and collaborate with your auditor when using one of our preferred partners.
Compliance considerations
While having SOC 2 reports is important for due diligence, the absence of a vendor's SOC 2 report typically won't be a blocker for your own compliance efforts. However, if your data is stored with a third-party vendor, ensuring they have SOC 2 compliance becomes more critical to avoid potential compliance gaps during audits.