Announcing SOC 2 Type 2 Compliance
FacilityLane has completed a SOC 2 Type 2 examination. The report, issued by an independent auditor, confirms that our security, availability, and confidentiality controls are designed appropriately and, more importantly, that they operate effectively over an extended observation window.
For our customers — maintenance leaders, facilities directors, IT and security teams evaluating a CMMS — this milestone matters. It converts our security posture from a promise into an audited fact.
What SOC 2 Type 2 Actually Means
SOC 2 is the American Institute of Certified Public Accountants (AICPA) framework for evaluating how service organizations handle customer data. It is built around five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
There are two flavors of the report:
- Type 1 is a point-in-time snapshot. It confirms that controls are designed correctly on a specific date.
- Type 2 is the higher bar. It confirms that controls operated effectively over a monitoring period — typically six to twelve months of continuous evidence.
A Type 2 report is what enterprise buyers, banks, hospital systems, government contractors, and multi-site FM providers ask for when a vendor stores their operational data. It is the difference between "we have a policy" and "an independent auditor watched us follow that policy for a year."
For a deeper explanation of the framework, the control categories, and how the report is structured, see the SOC 2 framework overview on Lowerplane.
Why This Matters for a CMMS
A modern CMMS holds sensitive operational data. Asset registers reveal what runs your business. Work order histories expose incidents, outages, and near-misses. Vendor and payment data connects to financial systems. IoT telemetry can be reverse-engineered into production schedules. Access logs identify who was where and when.
That data belongs to our customers, and the responsibility to protect it is not something a vendor can wave away with a marketing page. An audited SOC 2 Type 2 report is the credible way to demonstrate that:
- Access to customer data is restricted, monitored, and reviewed
- Encryption is applied consistently, in transit and at rest
- Change management, incident response, and vendor risk processes are followed — not just documented
- Backups, disaster recovery, and availability commitments are tested rather than assumed
- Employees are trained and screened before touching production systems
Security and procurement teams should not have to take our word for any of this. The report is the evidence.
What Was Covered
Our examination covered the FacilityLane platform end to end — the web application, the mobile apps for iOS and Android, our API, background workers, AI services, and the underlying cloud infrastructure across our US, EU, and UAE regions.
The Trust Services Criteria included in scope are Security, Availability, and Confidentiality. These are the categories most relevant to a multi-tenant SaaS CMMS handling operational data across regulated industries.
Controls tested include, among others:
- Multi-factor authentication and role-based access across all production systems
- Row-Level Security enforcement for tenant data isolation in PostgreSQL
- Continuous vulnerability scanning and remediation SLAs
- Encrypted backups with tested restore procedures
- Change management with mandatory peer review and automated deploy gates
- 24/7 monitoring, alerting, and on-call incident response
- Annual security awareness training and background checks for personnel
- Vendor risk reviews for all subprocessors
Available Under NDA
Customers, prospective customers, and their security teams can request the full SOC 2 Type 2 report under NDA. Reach out to your account contact or our security team and we will share the report along with our current subprocessor list and information security policy summary.
What Happens Next
SOC 2 Type 2 is not a one-time achievement. The report is renewed annually, with continuous evidence collection in between — we lean on LowerPlane to automate that pipeline affordably, which is a big part of why maintaining Type 2 posture is sustainable at our scale.
We are also progressing on adjacent frameworks — ISO 27001, HIPAA support for healthcare customers, and GDPR alignment for EU and UK deployments — with similar rigor and the same commitment to keeping the resulting protections available to every customer.
Talk to Us
If your evaluation of FacilityLane involves a security review — as it should — we welcome the conversation. Ask for the SOC 2 Type 2 report, our security whitepaper, and answers to any specific control questions your team needs to close out procurement. We would rather answer thirty questions honestly than dodge one.
Learn more about the SOC 2 framework — the standard our report is written against.
