A few weeks ago we asked ourselves a simple question: could you build a "free SOC 2 checker" - type in a domain, get a grade? Technically, yes. Honestly, that question is most of what's wrong with this category, and it's why Trufend's report never uses the word "certified."
SOC 2 is not a score. It's an attestation, performed by a licensed CPA firm, confirming that an organization's controls meet a defined set of criteria over a period of time. It covers process - how you handle access, backups, incident response, vendor risk, and dozens of other things that live inside a company, not on its public website. No tool that only looks at a domain from the outside, ours included, can determine any of that.
What an external scan can actually tell you
TLS configuration. Whether security headers are set. Whether DNS is configured to stop someone spoofing your email domain. Whether a forgotten subdomain is quietly pointing at nothing, waiting for someone to claim it. These are real, useful things to know - and they're maybe a fifth of what an auditor will eventually ask about.
Each of those is a genuine subject in its own right. We've since written them up individually: TLS configuration, security headers, email authentication and subdomain takeover. Useful, all of them. Still a fifth.
We built Trufend's report to reflect that ratio honestly, instead of dressing up ten header checks as if they added up to something bigger. Every report says, in plain words, "not a certification" - not in six-point footer type, but next to the grade, where you're actually looking.
Why this is the more useful version, not the safer one
A tool that quietly implies more than it can prove is a tool a good engineer stops trusting the moment they notice the gap. We'd rather you trust the slice we do show you, and use it as a starting point for the much larger slice that actually gets you to a real audit.
If you want the map of that larger slice, it's in the 80% a domain scan can't see. And if you want the standard itself explained properly, with the criteria, the timeline and the costs, start at what SOC 2 is and what it actually asks of you.