SSAE 16 Compliance Certification
Volico maintains SSAE 16 compliance through SOC 2 Type II and NIST audits.
Home / Data Center Services / Colocation Services / Certifications and Compliance / SSAE 16 Compliance
Volico operates enterprise-quality data centers built for mission-critical colocation, managed hosting, and cloud computing. We provide SSAE 16 and SOC 2 Type II audits, formerly known as SAS 70. Our team works with clients on their compliance requirements so they get the best value.
We also offer fully managed compliant infrastructures that exceed industry and regulatory standards. Whether you work in healthcare, retail, or financial services, our hands-on approach creates a customized solution for your business.
SSAE 16 IS DIVIDED INTO THREE TYPES OF SERVICE ORGANIZATION CONTROLS:
SSAE 16 (SOC 1) TYPE II
Volico is SSAE 16 and SAS 70 Type II certified. This compliant hosting helps clients meet their SSAE 16 and SAS 70 Type II audit requirements. In fact, SAS 70 has been the dominant in-depth audit of third-party service organizations for many years. The original Statement on Auditing Standards (SAS) No. 70 is one of many periodic statements from the Auditing Standards Board. That board sits within the American Institute of Certified Public Accountants (AICPA).
This certification confirms Volico’s controls are designed effectively, described accurately, and in operation. To reach SAS 70 Type II status, the auditor confirms the controls kept working well beyond the audit date.
SOC 2 & SOC 3
SOC 2 confirms clients we use systems to protect their data. It also audits security, availability, process integrity, privacy, and confidentiality in your data hosting environment. SOC 2 hosting assures your service provider has the best internal practices in place. This rigorous audit is challenging for service organizations to pass. It measures and reports on how well a service organization’s controls actually work. Unlike an SSAE 16 (SOC 1) audit, SOC 2 focuses on controls specific to IT and data center service providers. The SOC 2 report affects companies that host or store large amounts of data, particularly data centers. A SOC 2 report focuses on controls called Trust Services Principles: security, availability, confidentiality, processing integrity, and privacy. These principles validate that the system protects against unauthorized physical and logical access, for example.
SOC 3: The Public Summary Report
While SOC 2 is a confidential report, the SOC 3 report is publicly available. The report includes all the necessary certifications, but it is less detailed and technical than a SOC 2 report. A SOC 2 report lists every test an independent auditor performed, along with the results. Volico’s hosting solutions have been audited to prove certified SOC 3 hosting.
SOC 3 is a summary Trust Services Report that documents assurances on Volico’s controls related to the Security principle. Unlike SOC 2, it leaves out the detailed description of tests and results. SOC 3 hosting delivers an auditor’s opinion of SOC 2 components, plus an added seal of approval. That seal confirms your data center is audited and fully compliant. A SOC 3 report is a general-use document. As a result, anyone can distribute it publicly to show proper controls are in place within the data center’s system and design.
The SOC 3 report contains three parts. These include the auditor’s letter and summary opinion on the controls’ effectiveness. They also include a management attestation letter and a system description of the audited services.
Questions about SOC compliant hosting? Contact us for answers
REQUEST A FREE CONSULTATION
Schedule a time to meet with one of our compliance department experts.