Blog

/

SettLiT Is SOC 2 Type II Compliant. Here's Why That Matters for Your Cases.

SettLiT Is SOC 2 Type II Compliant. Here's Why That Matters for Your Cases.

SettLiT

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Summary

Type

No items found.

Keywords

No items found.

You already carry enough. Deadlines, depositions, a client who can't remember which urgent care they went to in 2019. The last thing you need is to wonder whether the vendor pulling that client's health data is protecting it properly.

So here's some added assurance: SettLiT is SOC 2 Type II compliant, with independent attestation of controls that were already part of how we operated. Prescient Assurance LLC (Prescient Security), an independent auditor, evaluated our existing security controls across a three-month observation window from February 17 to May 18, 2026. Their report, issued August 31, confirms those controls were suitably designed and operated effectively throughout the observation period.

What SOC 2 Type II actually means (in plain English)

SOC 2 is the AICPA's framework for evaluating the controls service organizations use to protect customer data and operate securely.

There are two kinds of SOC 2 reports. Type I is a snapshot: it evaluates whether controls are suitably designed as of a particular date. Type II is more like a film: auditors evaluate the controls over a period of time and test whether they operated effectively throughout that period. SettLiT went for the film. Access controls, code changes, security monitoring, and other key controls were tested over the observation period to determine whether they operated effectively. The result is an independent report that gives your managing partner, IT consultant, or client assurance about how the platform protects sensitive data.

Why compliance is the whole story, not a footnote

Digital health data access for plaintiff firms is new territory. The networks that hold this data, from EMRs to claims clearinghouses to state health information exchanges, don't open up to just anyone. They extend access to organizations they trust to handle it correctly.

SettLiT is built to operate within the national health data infrastructure, not around it. That's why we participate in the governance bodies that help shape the rules: DirectTrust, The Sequoia Project, CareQuality, and CARIN. SOC 2 Type II adds the independent, third-party proof on top.

Put simply: SettLiT is the compliant pipe between the national health data infrastructure and plaintiff law firms. Compliance-first digital health data. That has been the position from day one, and now an auditor has attested to it.

What this means for you

Faster vendor approval. If your firm, or a client's firm, runs security reviews before onboarding a vendor, the SOC 2 Type II report answers most of the questionnaire before it's sent. Request it through our Trust Center.

Defensible chain of custody. SettLiT already maintains full audit trails for every data transmission, so if opposing counsel challenges where a record came from, you can show it was pulled with authorization and wasn't altered in transit. The SOC 2 report shows the controls around that audit trail are independently tested.

One less thing to worry about. Your client signed an authorization. You trusted us with it. Now there's proof that trust was well placed, backed by encryption in transit and at rest, least-privilege access, and continuous monitoring.

Why it took more than a year (and why you should want it to)

Here's the part most announcements skip.

The observation window was three months. Getting to the start of it took more than a year. That's not a complaint. That's the point.

You know what it's like to build a case that has to hold up under scrutiny. Every fact needs a source. Every source needs a chain of custody. A SOC 2 Type II audit is the same discipline applied to a company. You don't get to describe your security. You have to support it with evidence across the observation period.

So before an auditor ever showed up, our team mapped every existing control to the AICPA's Trust Services Criteria and closed the gaps. Policies that lived in people's heads became documented, reviewable procedures. Infrastructure got hardened. Access got tighter. Logging expanded to cover everything that touches client data.

We connected our systems to Vanta so controls could be monitored continuously instead of checked once a year. Every employee, from engineering to sales, completed security and privacy training, acknowledged company policies, and brought their devices into compliance. When something drifted, Vanta flagged it and it got fixed in days, not discovered months later.

Then the window opened on February 17, 2026, and for three months the controls had to hold. No cramming. Either the evidence exists for the whole period or it doesn't.

Through the summer, Prescient Assurance worked through round after round of evidence requests and walkthroughs. Our compliance lead coordinated every one. Our operations team chased down and closed each flagged item. Our engineering team demonstrated that the technical controls were built right and kept right. On August 31, the auditor signed the report.

If you've ever wondered what separates a vendor that says "we take security seriously" from one that can prove it, this is it. A year of unglamorous, careful work so that when you hand us a client's authorization, you know exactly what happens next.

Same platform, same protection

SettLiT is powered by Marble, the health data infrastructure company that operates within the national interoperability frameworks. Marble chose to put the whole platform through a Type II audit, not just one product, because the networks SettLiT queries on your behalf (EMRs, claims clearinghouses, state exchanges) extend access based on organizational trust. That trust has to be earned at the infrastructure level and proven independently. Marble did the year of work. SettLiT customers get the report.

What happens next

A Type II report isn't a trophy you put on a shelf. The next observation window has already started, our controls stay under continuous monitoring through Vanta, and we'll renew the attestation every year.

See our articles