Skip to main content

Goodworld SOC 2 Type II Certification Overview

Understanding Goodworld's SOC 2 Type II Attestation and what our independent audit says about the strength of our data security and compliance controls

Written by Richie Kendall

What is SOC 2 Type II?

SOC 2 (Service Organization Control 2) is an auditing standard developed by the American Institute of Certified Public Accountants (AICPA) that evaluates how service organizations manage and protect customer data.

A SOC 2 Type II report provides independent verification that an organization's security controls are not only suitably designed, but have also been operating effectively over a sustained period of time — typically 6 to 12 months. This is what distinguishes Type II from Type I: rather than assessing controls at a single moment, a Type II audit tests whether those controls actually held up in practice, day after day, over the review period.


Goodworld's SOC 2 Type II Certification

Goodworld has successfully completed a SOC 2 Type II audit conducted by an independent, AICPA-accredited Certified Public Accountant (CPA). This certification demonstrates that our security controls were independently observed and verified to operate effectively over the audit period of [start date] to [end date].

Our SOC 2 Type II attestation covers the following Trust Services Criteria:

  • Security: Protection of system resources against unauthorized access

  • Availability: System availability for operation and use as committed or agreed

  • Processing Integrity: System processing is complete, valid, accurate, timely, and authorized

  • Confidentiality: Information designated as confidential is protected as committed or agreed

  • Privacy: Personal information is collected, used, retained, disclosed, and disposed of in conformity with commitments and applicable privacy standards


What Does This Mean for Your Organization?

Independent Verification A qualified third-party auditor examined our systems over an extended period and confirmed that our security controls are not only properly designed, but consistently operating as intended.

Industry Standards Our security practices meet the strict requirements established by the AICPA, which are recognized across the technology and financial services industries.

Stronger Assurance Because Type II testing spans months of continuous operation rather than a single point in time, it provides a higher level of assurance than Type I that our controls function reliably under real-world conditions.

Risk Mitigation We have documented policies, procedures, and technical controls in place to protect your data from unauthorized access, loss, or misuse — and those controls have now been proven effective over time.

Compliance Assurance Our SOC 2 Type II certification provides evidence that can help your organization meet its own compliance and vendor-risk requirements when working with third-party service providers.

Ongoing Commitment We maintain these controls on an ongoing basis and undergo regular annual audits to ensure continued Type II compliance.


How to Request Our SOC 2 Report

Goodworld's SOC 2 Type II Letter of Attestation is below, and the full report can be made available to current and prospective clients upon request.

To request access to our SOC 2 Type II report:

  1. Contact your Goodworld account manager, or

  2. Email hello@goodworldnow.com with "SOC 2 Report Request" in the subject line

  3. Include your organization name, contact information, and intended use

Once requested, we will provide secure access to the complete SOC 2 Type II report.

[Insert updated Type II attestation letter/report cover image]


What's Covered in Our SOC 2 Audit

Our SOC 2 Type II audit scope includes:

  • Access Controls: User authentication, authorization, and data access management

  • Network Security: Firewalls, encryption, and secure communication protocols

  • Data Protection: Encryption for data at rest and in transit; tokenization via Stripe

  • Physical Security: AWS data center security measures for MongoDB hosting

  • Vendor Management: Evaluation and oversight of third-party service providers

  • Incident Response: Detection, response, and management of security incidents

  • Change Management: Controlled processes for system and application updates

  • Risk Management: Identification and mitigation of security risks

[Confirm whether Type II testing expanded this scope — update if so]


Complementary Security Measures

Beyond our SOC 2 Type II certification, Goodworld maintains additional compliance and security standards:

  • PCI DSS Compliance: Annual SAQ-A and SAQ-D validation with Stripe (PCI Level 1)

  • CCPA Compliance: Adherence to California Consumer Privacy Act requirements

  • DPA Compliance: Data Protection Act standards

  • GDPR Compliance: Compliance for EU resident data

  • External Audits: Annual Third-Party Risk Management audits and Penetration Testing by Mastercard

  • Banking-Grade Security: System incubated within the banking sector through partnerships with Barclays Bank


Frequently Asked Questions

Q: What's the difference between SOC 2 Type I and Type II? A: Type I evaluates the design of controls at a specific point in time. Type II — which Goodworld has now achieved — assesses whether those controls operated effectively over a sustained period (typically 6–12 months), providing a stronger level of assurance than Type I alone.

Q: How often is the SOC 2 audit performed? A: Annually, to maintain certification and ensure controls remain effective on an ongoing basis.

Q: Does this guarantee my data is secure? A: No certification can guarantee absolute security, but SOC 2 Type II provides independent verification that our controls are properly designed and consistently operating effectively, meeting industry standards.

Q: Who performed the audit? A: The audit was conducted by an independent, AICPA-accredited CPA firm specializing in SOC audits.

Q: Can I share the SOC 2 report with my auditors? A: Yes, under NDA, it can be shared with authorized internal auditors or compliance teams.

Q: Does SOC 2 cover financial data? A: SOC 2 focuses on data protection controls. Payment processing is handled by Stripe, a PCI Level 1 Service Provider. All financial data is tokenized and never directly handled by Goodworld.


Additional Resources

For more details on Goodworld's security practices:


Notes for internal review before publishing:

  • Fill in the actual Type II audit period dates.

  • Swap in the new Type II attestation letter image (replacing the Type I screenshot).

  • Confirm whether audit scope changed under Type II and update the "What's Covered" list if needed.

  • Consider whether to keep this as a standalone updated article or add a redirect from the old Type I URL/slug.

Did this answer your question?