Editorial standards

How evidence becomes a SOC2Market claim.

Automation helps find and structure sources. It does not decide truth. Material claims require retained provenance and an explicit review decision before they can appear as facts.

Source hierarchy

Different sources support different conclusions.

Source classExamplesPublication treatment
Official primary sourceFirm, vendor, regulator, corporate filing or public trust centerHighest for claims the publisher can authoritatively make
Independent reportingIdentified newsroom, research organization or public recordUsed for events with date and attribution
Attributed user reportPermitted review, forum or submitted observationA signal; never treated alone as proof of a breach or credential
InferenceDerived from indirect evidenceLabeled inferred or withheld; never upgraded to confirmed

Collection and extraction

SOC2Market requests ordinary HTML first. Browser automation is reserved for permitted pages that require JavaScript or resist a direct request. Deterministic rules identify common frameworks, integrations and public SOC 2 language. Structured AI can propose claims, but each proposal must retain its source URL, a supporting excerpt, collection time, confidence score and content hash.

A content hash detects that a captured source changed; it does not prove the source was accurate. Material changes return affected records to review instead of silently preserving an old conclusion.

What we do not infer

We do not manufacture private pricing, audit timelines, credentials, customer relationships, integrations, incidents, breaches, layoffs or report-expiry dates. A logo, search snippet, sales claim or missing public report is insufficient evidence for those conclusions. “Not publicly verified” means exactly that—not that the claim is false.

Publication workflow

Draft → review → published or rejected.

01

Draft

A collector stores the candidate and its provenance.

02

Review

Evidence relevance, excerpt support, confidence, duplication and materiality are checked.

03

Publish

Only approved fields become available to public data queries.

04

Refresh

Sources are revisited; changed claims can return to review.

Search publication thresholds

A technically valid route is not automatically an indexable page. Auditor facets require multiple eligible firms. Vendor comparisons require reviewed evidence for both products and a minimum combined claim count. Company directories and research benchmarks remain noindex until their coverage thresholds are met. Sitemap generation applies the same rules.

Commercial separation

Featured profiles, category sponsorship and research support must be labeled. Payment cannot publish an unsupported claim, alter an evidence score, suppress an event, or change an editorial ordering. Lead-generation relationships are kept outside the evidence-review decision.

Corrections and source updates

Send the exact page, disputed statement, and supporting public source to research@soc2atlas.com. A correction request is reviewed against evidence; it is not a paid removal process.

SOC 1SOC 2SOC 3Type IType IIAudit readinessTrust centersVendor riskSecurity evidenceProcurement