1. The short version
cybersoftware is a SOC 2 compliance platform built by a small team. We help your startup get a real SOC 2 Type 1 or Type 2 report. Entry is a one-time fee and you choose at checkout whether it includes the Type 1 examination. Type 2 runs a full twelve-month term billed monthly, and your first Type 2 audit is included in it. You always own your data and can export it at any time. Below is the legal version of those promises.
2. Who you're agreeing with
"cybersoftware" or "we" / "us" / "our" means cybersoftware, a company organized in the United States. "You" or "your" means the person or business entity that signs up for an account on this website. By creating an account, paying for a cybersoftware service, or otherwise using the platform, you agree to these terms.
3. What the service is
cybersoftware provides software, content, and process management to help your company prepare for, complete, and maintain a SOC 2 examination. This includes intake assessment, deterministic gap identification, AI-generated policies and documentation, evidence collection workflow, report generation, and coordination with an independent U.S. CPA firm engaged to perform the examination. The platform is hosted, browser-based, and currently English-only.
cybersoftware is not a CPA firm and does not perform the SOC 2 examination itself. The audit opinion is issued by the independent CPA firm assigned to your engagement. We act as a technology provider and project coordinator.
4. Pricing and payment
Pricing is published on the pricing section of this site. The clauses below state the model as of the date of these terms.
Entry is a choice you make at checkout. Onboarding on its own is a one-time payment of $2,000 USD and covers platform onboarding without a SOC 2 Type 1 examination. Onboarding together with the Type 1 examination and report is a one-time payment of $4,000 USD, which includes the CPA firm engagement fee.
SOC 2 Type 2 runs on a 12 month term billed at $600 USD per month. The term runs the full 12 months and you owe the whole term. Monthly billing is a payment schedule, not a month to month contract, and it does not shorten what is owed.
You may instead pay the term in full. A single invoice of $7,000 USD covers the first 12 months, $200 less than twelve monthly payments, after which the account continues at the monthly rate unless cancelled.
Your first SOC 2 Type 2 audit is included in the term. It begins automatically once the 3 month observation period completes.
Additional Type 2 audits are arranged on request. Our team negotiates with independent audit firms on your behalf, and every engagement is quoted before it begins.
Cancelling inside the term. Billing and access continue to the end of the committed 12 months and then stop. There is no separate early termination fee.
Acceptance. Your acceptance of the term is recorded when you subscribe.
Entry payments are collected by Stripe at checkout. Type 2 charges are collected on the same recurring date each cycle for the length of the term. If a recurring payment fails, you receive a seven-day grace period during which Type 2 features remain available; after that, Type 2 features pause until your payment method is updated. Your Type 1 audit report and any completed Type 2 audit reports remain accessible regardless of subscription status. The intake, gap analysis, and policy drafting tools are free to use prior to payment. We may change pricing for new customers from time to time; existing engagements and active subscriptions are not retroactively repriced.
5. Refunds
Refund eligibility, request process, and timing are described in our Refund Policy, which is incorporated into these terms by reference.
6. Your account and conduct
You are responsible for keeping your account credentials secure, providing accurate information during intake, and ensuring that any team members granted access to your engagement are authorized to act on your behalf. You agree not to use cybersoftware to misrepresent the security posture of your company, fabricate evidence, or otherwise undermine the integrity of the SOC 2 examination. We may suspend or terminate access to any account engaged in such conduct.
7. Auditor independence
AICPA professional standards require that the CPA firm performing your SOC 2 examination remain structurally independent from cybersoftware. cybersoftware does not draft audit conclusions, influence findings, or share equity, fees, or referral compensation with any auditor in our network. The firm engaged for your examination is an independent, licensed U.S. CPA firm, and its identity is available on request before you sign the engagement letter.
8. Your data
All evidence files, policy drafts, intake responses, and audit artifacts you submit to cybersoftware remain your property. We process this data solely to deliver the service: generate policies tied to your specific environment, surface gaps, map evidence to controls, and prepare the package the auditor reviews. We do not sell your data, train AI models on your data, or use your data to benefit other customers. Our Privacy Policy describes in full what we collect, how we use it, and who we share it with.
Evidence files are stored encrypted in AWS S3 with access restricted by signed URLs available only to you and your assigned auditor. Backend logging is limited to operational telemetry (no body content). You may export or delete your data at any time by emailing surya@cybersoftware.com; we honor export requests within 30 days and delete requests within 60 days, subject to legal retention obligations.
9. AI-generated content
cybersoftware uses large language models (currently AWS Bedrock with Anthropic Claude) to draft policies, gap remediation guidance, and report narrative tied to your intake answers and evidence. AI output is generated from your data, not templates with your name swapped in, and is grounded in evidence you provide. But it is not infallible. You and your assigned auditor are the final reviewers. You agree to review every generated policy before it is delivered to your auditor, and you accept responsibility for the controls actually implemented in your environment.
10. Service availability and changes
We aim for high availability but do not guarantee uninterrupted service. We may add, modify, or discontinue features without prior notice. Material changes that affect an active engagement (such as removing a feature you depend on mid-audit) will be announced by email at least 14 days in advance.
11. Intellectual property
The cybersoftware platform, including software, design, brand assets, and proprietary algorithms, is owned by cybersoftware. We grant you a non-exclusive, non-transferable license to use the platform for the purpose of obtaining a SOC 2 examination of your own company during the period of your engagement. Generated policies become your property once delivered, and you may use, modify, or republish them as your own internal documents.
12. Disclaimers
cybersoftware is provided "as is" and "as available" without warranties of any kind, express or implied, including warranties of merchantability, fitness for a particular purpose, accuracy, or non-infringement. We do not warrant that the SOC 2 examination will result in a clean opinion, that your customers will accept the report for their security review, or that any specific gap will be remediated by use of the platform alone. Audit outcomes depend on the controls you actually implement and operate.
13. Limitation of liability
To the maximum extent permitted by law, cybersoftware's total liability arising out of or related to these terms or your use of the service is limited to the amount you paid cybersoftware in the twelve months preceding the claim. We are not liable for indirect, incidental, special, consequential, or punitive damages, including lost revenue, lost customers, or reputational harm, even if advised of the possibility of such damages. Some jurisdictions do not allow this limitation; in those jurisdictions our liability is limited to the maximum extent permitted by applicable law.
14. Indemnification
You agree to defend and indemnify cybersoftware and its officers, employees, and contractors from any third-party claims, damages, or expenses (including reasonable attorneys' fees) arising from (a) your misuse of the platform, (b) your violation of these terms, or (c) any false or misleading information you provided during intake or evidence collection that contributed to a flawed audit outcome.
15. Termination
You may stop using cybersoftware at any time by closing your account. We may suspend or terminate access for material breach of these terms, suspected fraud, or non-payment after notice and opportunity to cure. Upon termination, your right to use the platform ends, but your data export rights, our confidentiality obligations, and the limitation-of-liability and indemnification clauses survive.
16. Governing law and disputes
These terms are governed by the laws of the State of Delaware, United States, without regard to conflict-of-law provisions. Any dispute that cannot be resolved informally will be resolved by binding arbitration administered by JAMS in San Francisco, California, except that either party may bring an action in small-claims court for claims within that court's jurisdiction. You waive your right to participate in a class action against cybersoftware.
17. Changes to these terms
We may update these terms when product, legal, or business circumstances change. The "Last updated" date at the top reflects the most recent change. Material changes will be announced by email to active customers at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.
18. Contact
Questions, concerns, or legal notices should go to surya@cybersoftware.com. We respond to legal correspondence within 5 business days.
Plain-English footnote: we are a small startup. We genuinely want you to succeed at SOC 2, not to wrap you in legalese. If anything in here surprises you or seems unfair, email Surya directly. We will read it and probably change it.