F2 First SOC 2 Navigator
Startup SOC 2 search page

Publish a startup trust page that does not overclaim SOC 2.

Plan a startup SOC 2 trust page before certification with honest status language, evidence categories, owner accountability, and questionnaire-ready next steps.

Complete triage

Lead with current security posture

A pre-certification trust page should explain what the product does, how customer data is protected, which controls are already operating, and where SOC 2 readiness or audit work stands today.

Use status labels carefully

If the report is not complete, label the page around readiness, audit path, or in-progress controls. Do not use completed badges or wording that implies an auditor has already attested to the controls.

Give procurement somewhere to go

Add a simple path for security questionnaires: the owner to contact, evidence categories that can be shared, target timing where known, and the readiness packet the team can review internally before responding.

Keep sensitive evidence private

A public trust page can summarize controls, but detailed screenshots, customer records, keys, private policies, and confidential audit evidence should remain out of the browser planner and out of public HTML.

Connect the trust page to readiness work

The Navigator gives the team a weekly owner plan and evidence examples so the trust page reflects actual readiness work rather than becoming a static marketing page.

Readiness boundary

Founder-grade readiness guidance, not an auditor opinion.

Can a startup have a SOC 2 trust page before certification?

Yes, if it is framed as current security posture and readiness status rather than a completed SOC 2 certification or auditor attestation.

What belongs on a pre-certification trust page?

Include product security posture, readiness status, contact path, evidence categories, control-owner accountability, and boundaries around what is not yet complete.

Should public trust pages include audit evidence?

Usually no. Summarize evidence categories publicly and share detailed artifacts only through the team's approved security-review process.

Use the Navigator to align scope, owners, and evidence before auditor review. This is founder-grade readiness guidance, not legal advice, auditor attestation, or a SOC 2 certification. Do not enter secrets, customer records, private keys, or legal conclusions.