Attestation available today, examination scheduled
Our SOC 2 position, and what we can give you now
We do not hold a SOC 2 Type 1 or Type 2 report. Rather than leave your diligence team with nothing, we issue a signed management attestation, an extract of our control register with the evidence behind each control, and a walkthrough where your team names the controls and we show what backs them, including the ones that fail.
22
Controls operating
27
Controls in the register
23 percent
Pre-audit checklist complete
Available on request today
Signed management attestation
A letter signed by the chief executive stating the control set we operate, the frameworks it is aligned to, the controls not yet in place, and the date of the last register review.
It is not an independent auditor's opinion. It is management's own statement, and it says so in its opening paragraph.
Available immediately on request, dated the day it is issued.
Control register extract
The controls relevant to your engagement, each with the framework reference, the owner, the evidence that proves it, and its current status.
It is not a report of tested effectiveness across a period.
Available immediately on request, scoped to your engagement.
Evidence walkthrough
A scheduled session where your security or procurement team names controls and we show the dated evidence behind them, including anything that fails.
It is not a substitute for an examination, and we do not present it as one.
Available within five working days of a request.
Not available, and we will not imply otherwise
- Completed security questionnaire. It is not a claim of certification in a different format. Returned within five working days for a standard questionnaire.
- SOC 2 Type 1 report. It is not something we hold today, and we will not describe our own documents as one. Not available. A Type 1 examination follows the readiness program, and a Type 2 report follows a minimum of six months of clean evidence after that. We will tell you the honest position on the day you ask.
- Bridge letter. It is not meaningful without a report to bridge from, so it is issued only once a report exists. Not available until the first examination is complete.
What the attestation says
The letter is signed by Cleandra LeSane, Chief Executive Officer, Dephiant Consulting Inc. and reissued with each register review. These are its sections, in the order they appear.
- Purpose and limitations of this attestation
- This document is a statement by the management of Dephiant Consulting Inc. about the security controls the company operates. It is not an independent auditor's report, and it is not a SOC 2 report of any type. Dephiant Consulting Inc. does not hold a SOC 2 Type 1 or Type 2 report, an ISO 27001 certificate, a CMMC certification, or a FedRAMP authorization. Any party relying on this document should read it as management's own assertion, supported by dated evidence that is available for inspection, and nothing more than that.
- Scope of the control set
- The audit scope is the advisory and assessment services we deliver to clients, the systems that hold client information, and the people who deliver that work. It covers the Security trust services category, plus Availability and Confidentiality, because clients depend on us holding their material safely and returning it on time. Processing Integrity is out of scope, because we do not process client transactions.
- Management assertion
- Management asserts that the controls described in the attached register are documented, assigned to a named owner, and operating as described, except for those controls recorded with a status of in progress or planned, which are listed separately with the window in which they are scheduled. Management asserts that We operate a documented control set aligned to SOC 2 trust services criteria, ISO 27001 Annex A, and the NIST SP 800-171 practices that CMMC Level 2 assesses. We hold no SOC 2 report and no CMMC certification, because those come from an independent auditor or an authorized assessor. What we do hold is a register of controls, named owners, and dated evidence, which we review every quarter and will walk a client or their auditor through on request.
- How the register is maintained
- The register is reviewed on this cadence: Every quarter, with three controls tested in depth each cycle so every control is tested at least once a year. Client security questionnaires and vendor diligence requests are answered from this register only. Nobody answers a diligence question from memory. Where the register and any public statement disagree, the public statement is corrected, not the register.
- Controls not yet in place
- Controls recorded as in progress or planned are listed in the attached extract with the scheduled window and the work that closes them. They are disclosed here rather than omitted, because a client discovering them later is worse for both parties.
- Client information handling
- Client material is held in approved stores only, separated by client, retained only as long as the engagement and the agreed retention period require, and returned or destroyed on request with a record of the destruction. Subcontractors are assessed and bound to the same obligations before they touch client material.
- Incident notification commitment
- Where an incident affects client material, the client contact named in the engagement is notified without undue delay and in any event within the window stated in the engagement agreement, with a factual position, the actions taken, and what we need from the client. A lessons review follows within ten working days.
- What we will do on request
- We will provide the register extract relevant to your engagement, walk your security or procurement team through the evidence behind any control you name, complete your own diligence questionnaire from the register, and state plainly where we do not hold something you require.
- Signature
- Signed for and on behalf of Dephiant Consulting Inc. by Cleandra LeSane, Chief Executive Officer, Dephiant Consulting Inc.. This attestation is reissued every quarter with the register review, and on request where a procurement needs a letter dated inside a stated window.
The route to a real report
Our readiness program runs in 5 phases and carries 17 pre-audit items, currently 23 percent complete. The examination sits in the final phase, Examination (Month 12 onward). Engage the examining firm, support the fieldwork, and receive the report. A Type 2 report needs a minimum observation period after that, so we will not put a date on it we cannot keep.