Skip to main content
Back to Home
Buyer guide

What SOC 2 Means for a Messaging Bridge

A buyer guide to SOC 2 reports and what to ask messaging vendors. SyncRivo does not currently hold a SOC 2 report.

Type I vs Type II

Type I assesses control design at a point in time; Type II tests how controls operated over an audit period

Ask for the Report

A vendor with a SOC 2 report can share it under NDA — check the scope, audit period and exceptions

SyncRivo's Status

No SOC 2 report today; security questionnaire and architecture review on request

Need a Security Review?

SyncRivo does not currently hold a SOC 2 report. Contact our security team for a security questionnaire and an architecture review.

Request Security Questionnaire

1. What SOC 2 Is

SOC 2 is an attestation framework from the AICPA. An independent CPA firm examines a service provider's controls against the Trust Services Criteria and issues a report. A Type I report looks at whether controls are suitably designed at a point in time; a Type II report tests whether those controls operated effectively over an audit period, typically several months to a year.

SOC 2 is not a certification and there is no pass/fail badge: the value is in the report itself — its scope, audit period, auditor's opinion and any exceptions. When a messaging vendor claims SOC 2, ask to see the report under NDA.

SyncRivo does not currently hold a SOC 2 report; we provide a security questionnaire and architecture review on request.

2. Trust Services Criteria for a Messaging Bridge

A SOC 2 report can cover up to five criteria. These three matter most when a vendor relays messages between Slack, Microsoft Teams, Google Chat, Webex and Zoom:

Security

The system is protected against unauthorized access, use, or modification.

  • How are the vendor's OAuth tokens for your chat platforms stored and protected?
  • Are inbound webhooks from each platform signature-verified?
  • Is MFA available or enforced for admin dashboard access?

Availability

The system is available for operation and use as committed or agreed.

  • What happens to messages when a destination platform is unavailable?
  • Is there a retry mechanism, and is it on by default?
  • What availability commitments, if any, are in the contract?

Confidentiality

Information designated as confidential is protected as committed or agreed.

  • Does the vendor store message content, or only message IDs?
  • Is data encrypted in transit and at rest, and which data exactly?
  • Where is the service hosted, and who are the sub-processors?

3. How SyncRivo Answers These Questions Today

Data handling

  • Message content is not stored on the normal relay path; only message IDs are kept so threads, edits and reactions stay in sync.
  • Files pass through memory only.
  • An optional retry queue temporarily holds undelivered messages.

Encryption & tokens

  • Encrypted in transit (TLS).
  • Provider OAuth tokens encrypted at rest.
  • Webhook signature verification on all five platforms.

Access control

  • Sign in with Google or email + password.
  • Optional MFA (TOTP, passkeys).
  • Owner, admin and member roles, plus an organization suspension kill switch.

Hosting & vendors

  • Hosted in the US on Google Cloud (us-central1).
  • DPA and sub-processor list available.
  • BAA available for Enterprise customers.

4. What to Ask Any Vendor

Whether or not a vendor has a SOC 2 report, a security review of a messaging bridge should cover:

• Report status: Do you have a SOC 2 Type I or Type II report? What is the audit period and which criteria are in scope?

• Data flow: Which message data is stored, where, and for how long?

• Admin approvals: Which permissions does the app request on each chat platform, and why?

SyncRivo does not currently hold a SOC 2 report; we provide a security questionnaire and architecture review on request.

Three-Platform Bridges

Connect three enterprise messaging platforms simultaneously with SyncRivo's cross-platform bridges.

cookie_consent.banner.aria_announcement
Cookie consent banner is now visible. This site uses cookies to create a better experience for you.