Introducing rakedoc-nano: a state-of-the-art open-weight VLM for document parsing

CloudRaker Achieves SOC 2 Type 2 Compliance

Back to journal

Today we're excited to announce that CloudRaker has completed its SOC 2 Type 2 examination. MJD Advisors, an independent auditor, reviewed our security controls — and, more importantly, verified that we operated them effectively, continuously, over the entire audit period. The full report is available to customers and prospects under NDA through our trust portal at trust.cloudraker.com.

For a company whose job is to be trusted with your most sensitive documents — contracts, medical records, financial statements — achieving SOC 2 Type 2 Compliance was table stakes, and we're glad to have an independent third party attest to it.

What SOC 2 Type 2 actually means

SOC 2 is a framework developed by the American Institute of Certified Public Accountants (AICPA) for evaluating how a service organization protects customer data, measured against the Trust Services Criteria.

The distinction that matters is Type 1 versus Type 2. A Type 1 report confirms your controls are properly designed at a single point in time. A Type 2 report goes further: the auditor observes your organization over a period of months and attests that those controls actually operated throughout — access reviews performed, changes tracked, incidents handled, vendors assessed, backups tested. Anyone can pass an inspection on a given day. Type 2 is evidence that security is how we run the company.

Why it matters for your documents

CloudRaker sits in the middle of workflows where the stakes are high: we parse, extract, redact, fill, and digitally sign documents that carry legal, medical, and financial weight. Increasingly, AI agents participate in those workflows too — which makes verifiable, independently audited controls more important, not less.

Field reviewsettled
Coverage limit$1,250,0005/5
Signature packetIssuedlocked
Evidence hashRecordedok
  1. Draft approved by Legal

  2. Signature packet issued

  3. Hash recorded on evidence log

Concretely, the examination covers the things our customers ask us about in every security review:

  • Access control — who can reach production systems and customer data, how that access is granted, reviewed, and revoked.
  • Change management — how code and infrastructure changes are reviewed, tested, and deployed.
  • Encryption and key custody — data encrypted in transit and at rest; our document-signing keys live in hardened key-management infrastructure that no human can touch.
  • Monitoring and incident response — how we detect, triage, and communicate about issues.
  • Vendor management — how we assess the sub-processors our platform depends on.

If you've been answering security questionnaires with "pending" next to our name, you can now replace that with a report.

How to get the report

Our entire security posture is documented on our trust portal: trust.cloudraker.com. You'll find our SOC 2 Type 2 report, security documentation, and sub-processor list, with access to the full report a click away.

What's next

We know a Type 2 report isn't a finish line, and the observation window never really closes. Our controls are monitored continuously, and we'll undergo this examination on a recurring basis, so the report on the trust portal stays current.

If you're evaluating CloudRaker and security is on your checklist — good. It's on ours too. Start at trust.cloudraker.com, and if your team needs anything beyond it, write to us at security@cloudraker.com.