Security isn't a feature we bolt on — it's a condition of doing the work we do. TrueWatch sits inside customers' production environments, observing the logs, metrics, traces, and now AI agent activity that keep modern systems running. That's a position of trust, and we treat it that way.
We're glad to share that TrueWatch has completed its SOC 2 Type II examination, building on the SOC 2 Type I attestation we achieved previously. The examination was conducted by EY (Ernst & Young), one of the world's leading professional services firms, over an observation period from July 2025 to June 2026. TrueWatch’s SOC 2 Type II audit evaluated our internal controls under the Security, Availability, Confidentiality, and Privacy Trust Services Criteria.
Why Type II is a bigger deal than Type I
Type I confirms that our controls are well-designed at a single point in time — a snapshot. Type II is the movie: an independent auditor tests whether those same controls actually operated effectively, consistently, across months of real production activity. It's the difference between showing someone the blueprint and letting them watch the building stand through every season.
Reaching Type II means TrueWatch's security practices aren't a one-time setup — they're how we operate, every day, under observation.
What TrueWatch's controls cover
This attestation reflects practices already built into how we run TrueWatch, including:
- Multi-factor authentication and role-based, least-privilege access controls
- Encryption of data in transit
- Security embedded directly into our development and deployment pipeline (DevSecOps)
- Regular penetration testing and vulnerability scanning
- A documented, tested incident response process
- Ongoing monitoring of infrastructure availability and performance
What this means for you
If you're evaluating TrueWatch — or already running Toby AI Agents and Toby TruePilot in production — SOC 2 Type II gives you something concrete to point to:
- Faster security reviews. A current Type II report can answer the bulk of a vendor security questionnaire directly, so your team spends less time chasing documentation.
- Independent proof, not a promise. You don't have to take our word for how we handle access, change management, or incident response — a third party has verified it against months of evidence.
- Confidence at the observability layer. TrueWatch sees your logs, metrics, traces, and agent activity. Type II is our answer to the obvious next question: who's watching how TrueWatch handles all of that.
What's next
A SOC 2 report reflects a point in time and is renewed annually, so this isn't a finish line, it's a checkpoint. We'll continue to test, tighten, and re-certify our controls as TrueWatch and the Toby AI Agents platform grow.
Frequently Asked Questions
Q: What's the difference between SOC 2 Type I and Type II?
A: Type I evaluates whether your security controls are well-designed at one point in time. Type II evaluates whether those controls actually worked, consistently, over an extended observation period — typically several months. Type II is the more rigorous of the two.
Q: Which Trust Services Criteria did TrueWatch's audit cover?
A: TrueWatch’s SOC 2 Type II audit evaluated our internal controls under the Security, Availability, Confidentiality, and Privacy Trust Services Criteria.
Q: How can I request TrueWatch's SOC 2 Type II report?
A: Existing customers and prospective buyers under a Non-Disclosure Agreement(NDA) can request a copy of TrueWatch’s SOC 2 Type II report for the audit period (July 1, 2025 – June 30, 2026) by contacting their TrueWatch Account Executive or Customer Success Manager, or by submitting a request through our Trust Center. To protect sensitive infrastructure control details, access to the full report requires an active NDA.
Q: Does this cover Toby AI Agents and Toby TruePilot?
A: The SOC 2 Type II report evaluates TrueWatch’s overarching organization-level security controls, cloud infrastructure operations, access management, and Secure Development Lifecycle (SDLC).While Toby AI Agents and Toby TruePilot are not audited as separate standalone products, they are developed, deployed, and hosted entirely within TrueWatch’s audited internal security and cloud environment. As a result, they are fully governed by and benefit from our SOC 2 Type II security controls.
