Choosing a Provider

SOC 2 and Data Security: What to Ask a Background Check Provider Before Handing Over Candidate Data

By Dale Whitfield · August 28, 2026

Ask your background check vendor for their SOC 2 report before you sign anything. If they hesitate, or don't know what you mean, that's your answer right there.

This company handles Social Security numbers and criminal records for every candidate you screen. Their security needs to hold up to real scrutiny, not just a line on their homepage.

I ran background checks for almost 30 years before I retired, and security wasn't something I thought hard about back then. It should have been. Here's what SOC 2 actually is, what it does and doesn't prove, and the questions worth asking on your next vendor call.

What SOC 2 actually is

SOC 2 stands for System and Organization Controls 2. It's an independent audit built by the American Institute of Certified Public Accountants, and it's been the standard way tech and data companies prove they handle sensitive information responsibly for years now. It's not a badge a vendor made up for their website.

An outside auditor, someone with no stake in the outcome, checks the company's actual security controls. Password policies. Who can access what data. How they handle a server going down. Whether changes to their systems get reviewed before they go live. Then the auditor writes up what they found.

There are two versions worth knowing apart. A Type I report checks controls at one point in time, like a snapshot. A Type II report checks whether those controls held up over months, usually six to twelve. Type II means more. Anybody can look good for one day.

Why this matters more for a background check company than most vendors

Think about what you're actually handing over. Full name, date of birth, Social Security number, address history, and criminal record details, for every candidate you screen. That's not the same risk as a project management tool losing your task list.

If that data leaks, it's your problem too, not just the vendor's. Your candidates' identities are out in the open, and your company's name is attached to how it happened. A vendor handling this kind of data without a current SOC 2 report is asking you to trust them on faith. I wouldn't.

What SOC 2 doesn't mean

Here's where I want to be straight with you. A SOC 2 report isn't a guarantee nothing will ever go wrong. It doesn't mean the company is unhackable, and it doesn't mean every employee follows every policy every single day.

What it actually tells you is narrower, and more useful, than that. An independent party looked at their controls and confirmed they exist and got followed during the period covered.

That's real information. It's just not a promise of perfection, and any vendor selling it to you that way is overselling.

One more thing worth knowing. SOC 2 reports aren't public documents you can just find online. A vendor sends you the actual report, usually under an NDA. If a company claims SOC 2 compliance but won't show you anything when you ask, that claim is worth nothing.

Not sure which provider fits your team? Answer a few questions and get matched, free.
Find Your Match

The questions to actually ask

Don't just ask "are you SOC 2 compliant" and accept a yes. That question is too easy to answer badly. Ask these instead, and expect specific answers, not a marketing line.

Can I see your SOC 2 report, or a bridge letter if you're between audit periods? A vendor with nothing to hide sends it over, usually after an NDA. One that stalls or gets cagey hasn't actually done the audit, or doesn't want you looking too closely at what it found.

Is my candidates' data encrypted at rest and in transit? "At rest" means the data sitting in their database. "In transit" means the data moving between their system and yours. Both should be encrypted, and a vendor who's been asked this before answers it in one sentence.

How long do you keep candidate data, and how do you actually delete it? Data doesn't need to sit around forever once a report's delivered. Ask for a specific retention period, and ask what "deletion" actually means. Gone from the screen you see, or genuinely gone.

What's your breach notification process, and how fast? Not if a breach happens, but when. Ask how quickly they'd tell you, and what they'd tell you. A vendor with a real answer has clearly thought about this before.

What a bad answer sounds like

"We take security very seriously" isn't an answer. Neither is a sales rep promising someone from their security team will follow up, and then never calling back.

A vendor with a real answer can say specific things. What their retention period actually is, in months or years. Whether encryption is on by default. Who at their company owns breach response, by title, not just "the team handles it."

If you get vague, confident-sounding answers instead of specifics, that's more trouble than its worth signing up for. Ask again in writing. A vendor that's actually done the work doesnt mind putting it on paper.