Checkpoint · SOC 2

SOC 2 software for Australian SaaS on Microsoft 365

Checkpoint carries the full set of Trust Services Criteria, evidences the security criteria from your Microsoft 365 tenant, and gives your sales team a Trust Center and ready answers to security questionnaires while you prepare for the audit.

The demo is the real console with sample data. No sign-up.

Checkpoint SOC 2 view: Trust Services Criteria with scope, status, the ISO 27001 controls they map to, owner, assurance and evidence
Checkpoint, demo tenant with sample data. Open this screen in the demo

What Checkpoint holds for SOC 2

  • The Trust Services Criteria (2017, revised 2022): the Common Criteria plus Availability, Confidentiality, Processing Integrity and the full Privacy series.
  • Cross-mapping to ISO 27001, so one programme can serve both.
  • A Trust Center page and answers to customer security questionnaires, built from your own evidence.
  • Risk register, policies, suppliers, incidents and access reviews in the same console.

Measured from your Microsoft 365

The Microsoft 365 scan evidences the access, change, monitoring and incident criteria from your tenant. Optional collectors add AWS (10 checks) and GitHub (7 checks), for SaaS teams that build there.

Checkpoint signs in with Microsoft Entra and reads your settings through Microsoft Graph with read-only, delegated permissions. Your records are SharePoint lists in your own tenant, so if you stop using Checkpoint they are still yours. How Checkpoint works.

Questions

Does Checkpoint issue the SOC 2 report?
No. A SOC 2 report is issued by a licensed CPA firm. Checkpoint prepares the controls and evidence the auditor tests.
Type I or Type II?
Both. Type II needs evidence across an observation period, and Checkpoint records the observation dates and keeps evidence dated throughout.
We host on AWS. Does that matter?
The optional AWS collector runs in your own AWS account and reports 10 checks to Checkpoint. Records still stay in your Microsoft 365 tenant.
Microsoft Teams