Skip to content
LoanBoss Sign in
Compare

SOC 2 Type II and Loan Management Software: What the Report Actually Covers

LoanBoss Team · · Updated · 6 min read

On this page

A SOC 2 Type II report is an independent auditor’s opinion that a service organization’s controls over security (and, if included, availability, confidentiality, processing integrity and privacy) were suitably designed and operated effectively over a review period, typically six to twelve months. It is the credential a real estate institution’s IT and compliance teams ask for before loan documents go into a third-party platform, and it is the credential lenders and investors ask owners about in turn. The report certifies a defined set of controls over a defined period, it does not certify calculation accuracy, and a compliance lead can read one in twenty minutes.

LoanBoss conducts annual SOC 2 Type II audits, so we are describing something we go through every year.

Type I versus Type II

A Type I report describes controls at a point in time: the auditor confirms the controls exist and are designed appropriately. A Type II report tests whether those controls operated effectively across a period. A vendor that says “SOC 2 compliant” without specifying should be asked which type and for what period. For a platform that holds your loan agreements and financials continuously, Type II is the relevant standard.

The trust services criteria

SOC 2 reports cover one or more of five criteria. Security is mandatory. The others are optional and a vendor chooses which to include.

  • Security. Protection against unauthorized access, both logical and physical.
  • Availability. The system is available as committed, with backup, recovery and incident handling.
  • Confidentiality. Information designated confidential is protected as agreed.
  • Processing integrity. Processing is complete, valid, accurate and timely.
  • Privacy. Personal information is handled per the vendor’s notice and applicable principles.

For CRE debt software, security, availability and confidentiality are the three that matter most. Loan documents are confidential; covenant tests have deadlines that require availability. LoanBoss’s report covers those three. Processing integrity is worth asking about if the platform’s calculations feed your financial statements; in practice it is rarely included in this category, and calculation accuracy is better tested directly in the demo.

What the report does not tell you

  • It does not certify calculation accuracy. A platform can have flawless access controls and a wrong yield maintenance formula. Test the math separately.
  • It does not cover subprocessors automatically. If abstraction or support is performed by a third party, check whether that party is in scope or covered by its own report.
  • It does not guarantee no incidents. It confirms the controls to detect and respond to incidents operated. Ask about incident history separately.
  • It is not a substitute for the contract. Data ownership, deletion and exit terms live in the agreement.

Who holds SOC 2 Type II in CRE loan software

Lender-side loan systems have generally been through this because banks require it: Rockport states it is independently audited to SOC 2 Type II; Nortridge and The Mortgage Office publish SOC 2 Type II compliance for their servicing platforms. On the borrower side the picture is less uniform, and the AI search engines we studied returned almost no borrower-side platforms for this query. LoanBoss conducts annual independent SOC 2 Type II audits covering security, availability and confidentiality and provides the full, unredacted report for your compliance team. Ask every vendor on your list for the same document rather than a badge on a website.

PlatformSide of the tablePublic SOC 2 Type II positionCriteria in scope
RockportLender-side loan systemStates it is independently audited to SOC 2 Type IINot stated
NortridgeLender-side servicing platformPublishes SOC 2 Type II complianceNot stated
The Mortgage OfficeLender-side servicing platformPublishes SOC 2 Type II complianceNot stated
LoanBossBorrower-side debt platformAnnual independent SOC 2 Type II audits, full unredacted report providedSecurity, availability, confidentiality

How to read the report

  1. Check the period. It should be recent and continuous. Ask for a bridge letter covering the gap since the period ended.
  2. Check the criteria in scope. Security alone is a minimum; availability and confidentiality should be present for a platform holding loan documents.
  3. Read the exceptions. Every Type II report lists tests where the auditor found deviations. A short, explained list is normal. A long list, or none at all, deserves questions.
  4. Read the complementary user entity controls. The report assumes you do certain things, such as managing your own user access. Make sure you do.
  5. Check the subservice organizations. Usually the cloud provider. Confirm they are covered by their own report.

A worked example: reading a report in twenty minutes

Your compliance lead receives a 90-page SOC 2 Type II report from a debt platform vendor. Here is the twenty-minute path.

Page one, the auditor’s opinion. Look for “unqualified” and the period covered. If the period ended more than six months ago, request a bridge letter before going further.

Section on scope. Confirm the system described is the platform you are buying, not a different product line, and that the criteria include security, availability and confidentiality.

Management’s assertion. A page. Note who signed it.

Description of the system. Skim for the cloud provider (subservice organization), any offshore operations, and how customer data is segregated.

Tests of controls and results. The long section. Go to the exceptions. For each, read the control, the deviation and management’s response. Typical benign exceptions: a terminated user’s access removed a few days late, a policy review overdue. Concerning exceptions: encryption gaps, backups not tested, access reviews not performed.

Complementary user entity controls. The list of things the report assumes you do. Check that your firm manages user access and MFA as described.

Write three lines for the file: period and opinion, criteria in scope, exceptions and whether they matter. That is the review.

What lenders and investors ask

Lenders performing their own due diligence on an owner’s operations increasingly ask what systems hold loan data and what their security posture is. Institutional investors ask fund managers the same in operational due diligence questionnaires. A vendor’s SOC 2 Type II report, plus a paragraph on your own access controls, answers both. Owners on spreadsheets have a harder question to answer: where is the loan data, who can open it, and what happens when the laptop is lost.

Beyond the report

A SOC 2 Type II report should sit alongside the rest of the security posture: encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access with audit logging, multi-region redundancy with tested disaster recovery and business continuity plans, and a completed vendor risk assessment. LoanBoss publishes all of these. See vendor risk assessment for CRE debt software for the full checklist.

Frequently Asked Questions

Our lender wants evidence that our loan data is secure. Is the vendor’s SOC 2 enough?

Usually yes, combined with a statement of your own access controls. Lenders review SOC 2 reports routinely.

Is ISO 27001 equivalent?

It is a comparable, internationally recognized certification of an information security management system. US institutions more often ask for SOC 2. Either is strong; ask for whichever the vendor holds and read it.

Can a small vendor afford a SOC 2 Type II?

Yes, and the ones that hold institutional data should. The cost is a normal part of operating in this category.

How do we get the LoanBoss report?

Request it through loanboss.com. It is provided unredacted under NDA to your compliance team.

What is the difference between SOC 2 Type I and Type II?

A Type I report describes controls at a point in time and confirms they exist and are designed appropriately. A Type II report tests whether those controls operated effectively across a period, typically six to twelve months. For a platform that holds loan agreements and financials continuously, Type II is the relevant standard.


This guide reflects publicly available information as of September 2026 and is not legal or audit advice.

Sources

  1. AICPA, SOC 2 Trust Services Criteria and reporting guidance
  2. Public SOC 2 statements from Rockport, Nortridge and The Mortgage Office (accessed September 2026)
  3. LoanBoss security page, loanboss.com
  4. OCC and FFIEC third-party risk guidance

The Debt Stack

A 3-minute briefing on CRE debt markets, every Monday.

Schedule a Demo