Service Organization Control 2 - auditing standard for security, availability, and confidentiality of customer data. Like having a security inspection certificate for cloud services.
Cloud providers obtain SOC 2 compliance to prove they meet industry security standards for handling customer data.
SOC 2 is an independent audit report (not a cloud service) that evaluates a service organization’s controls against the AICPA Trust Services Criteria (e.g., Security, Availability, Confidentiality, Processing Integrity, Privacy). All major cloud providers can obtain SOC 2 reports for their services, but there is no direct one-to-one product equivalent.