Asia Tech Times — Technology, science and culture across Asia

Technology, science and culture across Asia

Business Tech

One of Asia's first SOC 2 reports, and what it actually certifies

Horangi says it is among the first cybersecurity firms in Asia to hold a SOC 2 Type II report, an audit of its own controls rather than of its products.

Horangi says it has achieved SOC 2 Type II compliance, describing itself as one of the first cybersecurity companies in Asia to do so. The framework, developed by the American Institute of CPAs, sets out how a company handling customer data should manage security, availability and confidentiality; the auditors Coalfire tested Horangi's controls over a four-month period covering security and confidentiality.

The company says it wrote more than twenty policies and deployed them with its own Warden platform and the identity tool JumpCloud, and that the audit found the necessary criteria had been met. Horangi's chief executive, Paul Hadjy, calls it a year-long effort that put the firm's practices under an external eye.

What a SOC 2 report proves, and what it does not

A SOC 2 Type II report is a statement by an auditor about a company's controls during a defined window. It is not a guarantee that a product is secure, and it is not a certification of the software a customer buys. A firm can hold a clean report and still ship code with vulnerabilities; what the report speaks to is the discipline around the processes the auditors examined.

That distinction matters here because Horangi sells security. The report is evidence about the vendor's own housekeeping, which buyers increasingly ask for and few can assess directly. The announcement gives no scope statement, no list of exceptions and no date beyond the audit period, which are the parts of a report a serious buyer would want to read. The company also notes accreditations from Singapore's IMDA and its appointment to the SG Cyber Safe programme — markers that, like the SOC 2, say something about process and nothing about whether the software catches what it claims to.