Security is a priority we can demonstrate: our SOC 2 Type II attestation
Protecting customer data is not a box we tick once a year. A Type II report tests whether our controls held every day across a months-long window — and ours did. Here is what that means in practice.
Every file that moves through Dwelling Blocks relates to someone’s home: a street address, interior photographs, a homeowner’s name, a lender’s loan file. That is the material our customers entrust to us, and it is entirely reasonable to ask what protects it.
For the past several months, an independent auditor has been verifying the answer. That work is now complete: Dwelling Blocks holds a SOC 2 Type II attestation, issued under the AICPA’s SSAE 18 standard.
Why Type II is the harder standard
There are two kinds of SOC 2 report, and the distinction matters more than the names suggest.
A Type I report is a photograph. An auditor examines how controls are designed on a single day and documents what they find. The date is known in advance, and a company can prepare for it.
A Type II report is closer to reviewing the security footage. The auditor selects a window spanning months and tests whether each control operated correctly on every day within it. Evidence is sampled and must be produced on demand: an employee departed in March — was their access revoked within the required window, and what proves it? A change shipped to production in May — who reviewed and approved it beforehand?
That is a materially different bar. A control that exists on paper but is skipped during a demanding week will surface in the sample. It is why lenders ask for Type II specifically, and why we pursued it.
What the auditor examined
The report assesses the design and operating effectiveness of our controls against three questions:
- Security — can data be reached by anyone who should not have access to it?
- Availability — is the platform operating when our customers depend on it?
- Confidentiality — do we honour the specific commitments we make to lenders about how their data is handled?
What the controls require
The attestation rests on a detailed set of individual controls, spanning our infrastructure, our product, our internal procedures, our data handling, and our hiring. Several of the most consequential:
- Access is limited to those who require it. Privileged access to production databases, servers, and networks is restricted to personnel with a documented business need, and access is revoked on departure within a defined service level — not when someone remembers.
- Data is unreadable if it is ever removed from where it belongs. Customer data is encrypted at rest in our datastores and encrypted again in transit across public networks.
- No change reaches production unreviewed. Every modification to software or infrastructure is documented, tested, reviewed, and approved before deployment, and the ability to deploy is itself restricted.
- Recovery plans are tested, not merely written. Business continuity and disaster recovery plans are exercised at least annually, on the principle that an untested plan is a document rather than a plan.
- Personnel are part of the control set. Background checks before hire, signed confidentiality agreements, an enforced code of conduct, and security awareness training within thirty days of joining and annually thereafter.
- Data is removed when the relationship ends. Customer data is purged from our environment when a customer leaves the service. We do not retain it.
Published, and open to verification
A compliance badge confirms that an audit took place at some point in the past and asks the reader to assume nothing has lapsed since.
We publish more than that. Each control is listed at trust.dwellingblocks.com with the precise language that defines it and its current status. The controls are monitored continuously and the page records the time of its most recent check — typically minutes old rather than months. If a control drifts, it is visible there rather than in next year’s report.
This has two practical uses. Security reviewers will find most of a standard questionnaire already answered, and can assess us before scheduling a call. Lenders and vendors evaluating what happens to the files they send us can read the current position directly, in specifics rather than assurances.
Requesting the report
The Trust Center documents the controls; the report adds the auditor’s testing procedures and their formal opinion. Customers and prospective customers can request the full report through their account team, or by contacting us directly.
No attestation makes a system permanently secure, and we would not suggest otherwise. That is precisely why the observation window is a rolling one and the monitoring is continuous. The next period is already under way.