HomeBlog › Not a certification

Why we'll never call this a SOC 2 certificate

A domain scan could be dressed up as a compliance badge. Here's why Trufend's report deliberately isn't one.

Domain scan versus SOC 2 illustration: a small panel of passing external checks for TLS, certificate validity, open ports and known vulnerabilities, set against a far larger landscape labelled with the internal areas SOC 2 covers, including people and access, processes and policies, data protection, incident response, vendor management and risk governance.

A few weeks ago we asked ourselves a simple question: could you build a "free SOC 2 checker" - type in a domain, get a grade? Technically, yes. Honestly, that question is most of what's wrong with this category, and it's why Trufend's report never uses the word "certified."

SOC 2 is not a score. It's an attestation, performed by a licensed CPA firm, confirming that an organization's controls meet a defined set of criteria over a period of time. It covers process - how you handle access, backups, incident response, vendor risk, and dozens of other things that live inside a company, not on its public website. No tool that only looks at a domain from the outside, ours included, can determine any of that.

What an external scan can actually tell you

TLS configuration. Whether security headers are set. Whether DNS is configured to stop someone spoofing your email domain. Whether a forgotten subdomain is quietly pointing at nothing, waiting for someone to claim it. These are real, useful things to know - and they're maybe a fifth of what an auditor will eventually ask about.

Each of those is a genuine subject in its own right. We've since written them up individually: TLS configuration, security headers, email authentication and subdomain takeover. Useful, all of them. Still a fifth.

We built Trufend's report to reflect that ratio honestly, instead of dressing up ten header checks as if they added up to something bigger. Every report says, in plain words, "not a certification" - not in six-point footer type, but next to the grade, where you're actually looking.

Why this is the more useful version, not the safer one

A tool that quietly implies more than it can prove is a tool a good engineer stops trusting the moment they notice the gap. We'd rather you trust the slice we do show you, and use it as a starting point for the much larger slice that actually gets you to a real audit.

If you want the map of that larger slice, it's in the 80% a domain scan can't see. And if you want the standard itself explained properly, with the criteria, the timeline and the costs, start at what SOC 2 is and what it actually asks of you.

Questions people ask about this

Is an external security scan the same as SOC 2 compliance?

No. SOC 2 is an attestation performed by a licensed CPA firm, covering controls and process over a period of time. An external scan reads publicly visible configuration at a single moment. They are different things measuring different subjects.

Can any tool certify SOC 2 compliance automatically?

No. Certification requires an audit by a licensed CPA firm. Tools can help you prepare, collect evidence and monitor controls, but the attestation itself cannot be issued by software.

What is an external scan actually useful for?

Finding and fixing externally visible hygiene problems - TLS configuration, security headers, email authentication, exposed subdomains and assets - and establishing a baseline you can re-check after infrastructure changes.

See the scoped version

Ten external checks, clearly separated from the much larger part no scan can verify.

Run a free check