Estimates, and the process of building them, hold some of the most sensitive information a builder has. For many general contractors, that cost data is a competitive advantage built over decades, rarely shared outside the company.

When teams bring that data into Ediphi, they trust us to protect it. 

Which is why we’re proud to announce that Ediphi has completed its SOC 2 Type II examination, conducted by the independent auditors at Johanson Group LLP. This report gives customers independent evidence of how we protect their cost data.

What is SOC 2?

Let’s cut through some of the tech language.

SOC 2 (System and Organization Controls 2) is a carefully created framework, developed by the American Institute of Certified Public Accountants (AICPA), for evaluating exactly how service providers manage and protect customer data.

Independent auditors look at a company's controls against a bunch of criteria — security, availability, processing integrity, confidentiality, and privacy. Our examination covered the Security, Availability, and Confidentiality Trust Services Criteria.

There are two types of SOC 2 reports. 

  • A Type I report evaluates whether controls are properly designed at a single point in time. 
  • A Type II report takes it further. Auditors test whether those controls actually worked as intended across an extended observation period. It's the more rigorous of the two (and the one enterprise IT and security teams typically ask for).

Why now?

For a growing software company, a formal audit competes for time and resources with building the product itself. 

In our early years, we focused on building security into the platform directly. As Ediphi has matured and our customers have grown to include general contracting mammoths like DPR and Hensel Phelps, formalizing those practices through an independent audit became the natural next step.

It's also not a process you can rush; which is what makes it a good report. 

A Type II report can't be issued until auditors have watched our controls operate for months. They do more than read our policies; they check whether those policies hold up day after day, through real releases, real access changes, and real operations.

SOC 2 didn't suddenly introduce security to Ediphi. It put our existing practices to an outside test to give customers a way to verify them.

What this means for preconstruction

Before a contractor even looks at new software, IT and security teams usually need answers. 

How is data encrypted? Who has access? How are changes managed? What happens if something goes wrong? 

Those reviews add weeks to a buying process, especially when answers rest solely on a vendor's word.

A SOC 2 Type II report replaces some of that doubt with independent evidence. Auditors examined how Ediphi handles access control, change management, system monitoring, and incident response, and verified that those controls held up in practice, not just on paper.

For precon leaders, it means fewer obstacles between choosing a platform and putting it to work. For IT teams, it means a clear, third-party view of how estimating data is protected.

“Estimating data belongs to the builders who created it. Our job is to protect it as carefully as they would, and this report is how we show that we do” — Mike Navarro, CFO at Ediphi

An ongoing commitment

SOC 2 isn't a one-time milestone. We will undergo annual examinations, and security remains built into how we develop and operate Ediphi, from encryption at rest and in transit to ongoing monitoring of our systems

Customers and prospects can request a copy of our SOC 2 Type II report through our security page. 

A builder's cost history took years to earn. It should be treated that way.