Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A vendor’s SOC 2 report is usually a restricted document. You get it from the vendor’s trust center, a compliance area inside your account, or a request process, and what you can see depends on your account role, your plan, and whether you must sign an NDA or accept terms first. This guide gives the official route and access conditions for five vendors: AWS, Vercel, Supabase, GitHub, and Stripe. For any other provider, the general steps at the end apply.

Where each vendor keeps its report

Vendor Official route Who can get the SOC 2 report
AWS AWS console > AWS Artifact > View reports > AWS reports SOC 1 and SOC 2 require an NDA and Artifact access. SOC 3 is public and does not need Artifact access.
Vercel Vercel Trust Center > SOC 2 Report > Get access Access is requested through the Trust Center. Public download and eligibility are not stated on the indexed page.
Supabase Organization dashboard > Legal Documents Team or Enterprise plan customers only.
GitHub (Enterprise Cloud) Enterprise Compliance page > Resources Enterprise owners can download SOC 2 Type 2 (and SOC 1 Type 2).
GitHub (organization) Organization Settings > Security > Compliance Lists SOC 3 and other materials, not SOC 2.
Stripe Dashboard > Compliance & Documents > Stripe documents Dashboard Owners and Administrators. Terms may need to be accepted. No separate NDA is required for this route.

Choose the right report before you request it

A report answers a review only if its type, scope, and period match what you need to assess. Check three things before downloading.

  • Report type. SOC 1 reports address controls relevant to financial reporting. SOC 2 reports address the Trust Services Criteria, which include security, availability, processing integrity, confidentiality, and privacy. SOC 3 is a shorter, general-use summary. Vendors describe SOC 2 as an examination, and the document is a report rather than a certificate.
  • System scope. A report covers the products and systems named in it. Supabase cautions that its SOC 2 coverage does not extend to customer environments outside its own product and control, so you still need to assess your own responsibilities and the boundary the report draws.
  • Audit period. Check the dates the report covers. AWS Artifact displays the description and audit period for each document, which is the place to confirm them.

How to get each vendor’s report

AWS

  1. Sign in to the AWS console and open AWS Artifact.
  2. Choose View reports, then AWS reports.
  3. Read the description and audit period of each document and select the one that matches your review.
  4. For SOC 1 or SOC 2, complete the NDA step Artifact requires before the restricted report is available.
  5. For SOC 3, no Artifact access is needed because the report is public.

AWS re:Post explains how to download and share AWS Artifact documents. AWS also describes Artifact as a self-service portal for on-demand access to AWS and certain AWS Marketplace ISV compliance reports. That third-party feature is limited to the marketplace listings it covers, so do not expect Artifact to hold reports from vendors outside that context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Vercel

  1. Open the Vercel Trust Center.
  2. Find SOC 2 Report in the document list.
  3. Select Get access and complete the request.

The Trust Center invites users to request access to its security documents. Plan for a request step rather than an immediate download. The indexed page does not state who qualifies or how long approval takes.

Supabase

  1. Confirm that your organization is on the Team or Enterprise plan.
  2. Open the organization dashboard and go to Legal Documents.
  3. Find the SOC 2 Type 2 report there.

Supabase’s SOC 2 compliance documentation states: “To access the SOC 2 Type 2 report, you must be a Enterprise or Team Plan Supabase customer.” Accounts outside those two plans fall outside that statement.

GitHub

GitHub has two different routes, and the one that yields a SOC 2 report depends on whether you manage an enterprise or an organization.

  1. As an enterprise owner of GitHub Enterprise Cloud, open the enterprise’s Compliance page.
  2. Under Resources, download SOC 2 Type 2. SOC 1 Type 2 is listed there as well.

The organization route is Organization Settings > Security > Compliance. GitHub’s organization compliance documentation lists SOC 3 and other materials on that page, not SOC 2. If you only have organization access, the SOC 2 Type 2 report requires enterprise owner access. The enterprise compliance documentation describes the enterprise route.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Stripe

  1. Sign in as a Dashboard Owner or Administrator.
  2. Go to Compliance & Documents, then Stripe documents.
  3. Accept the terms if prompted.
  4. Download the report. Stripe watermarks downloads with your account details and the time you accepted the terms.

Stripe’s help article on downloading SOC reports says a separate NDA is not required for this route.

A public SOC 3 is not the restricted SOC 2 report

A SOC 3 report is a high-level summary that vendors publish for general audiences. AWS and Stripe both offer SOC 3 reports publicly. The SOC 2 report is the document with control-level detail, and it stays restricted. If a questionnaire or procurement process asks for a SOC 2 report, a public SOC 3 will not provide the same detail, so check which document the request names before you treat a SOC 3 download as the answer.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check the audit period and any bridge letter

  • Supabase: Its examination is annual, and its rolling 12-month report window runs from March 1 through February 28 of the following year, according to its 2026 documentation.
  • Stripe: Its help page says its SOC 1 and SOC 2 Type II reports cover design and operating effectiveness over a 6–12 month period. The page does not state a publication date.
  • Stripe bridge letters: Stripe says the Dashboard provides bridge letters that cover the period between its last issued SOC report and a future report. Use the dates on your own letter, not the example dates in the help article.

Do not infer a report’s issue date from these general descriptions. Confirm the current period in the vendor’s own portal.

When you cannot open the report

  • Stripe shows no Compliance & Documents entry: Your role is probably not Owner or Administrator. Ask an owner or administrator to download the report or grant you that role.
  • Stripe asks you to accept terms: Accept them before downloading. The acceptance time is recorded in the watermark.
  • Supabase shows no Legal Documents area: Check your plan. The SOC 2 Type 2 report is limited to Team and Enterprise customers.
  • GitHub organization page shows only SOC 3: Use the enterprise Compliance page, which requires enterprise owner access.
  • AWS SOC 1 or SOC 2 is not available: Complete the NDA step in AWS Artifact first. SOC 3 downloads do not require it.
  • Vercel offers no immediate download: Submit the access request through Get access and wait for a response.

Other vendors: a general approach

For providers not covered above, the same checklist applies.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Search the vendor’s security or trust page for SOC 2 and note which report types it lists.
  2. Check your account’s compliance or legal documents area, and note your role and plan.
  3. If nothing is published, ask the vendor’s account manager or security contact for the current SOC 2 report and the terms it requires, such as an NDA.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.