Case Studies

Download one-pagers, case studies, and white papers to learn how Lukka supports institutional data, pricing, compliance, analytics, and reporting workflows across digital assets.

One-Pagers

What is the scope of a SOC 2 report?

Per the AICPA, SOC 2 reports cover controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy. These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to security, availability, and processing integrity of the systems the service organization uses to process users’ data and the confidentiality and privacy of the information processed by these systems.

These reports can play an important role in: 

  • Oversight of the organization
  • Vendor management programs
  • Internal corporate governance and risk management processes
  • Regulatory oversight

Are all SOC 2 audits the same?

No, they are all custom-tailored to the specific Service Organization and can vary significantly. SOC 2 reports specifically may or may not include any of the 5 risk domain areas: Security, Availability, Processing Integrity, Confidentiality, and Privacy. We recommend asking any Service Organization that you plan on using as a vendor who their SOC auditor is, for a copy of the SOC report, whether it was a Type I or Type II (Type II is strongly preferred), and how many years the Service Organization has conducted SOC audits.

What time period is associated with Lukka’s Type II audits?

Lukka conducts both SOC 1 Type II and SOC 2 Type II audits annually. For the portion of the year outside of testing periods, we offer bridge letters to customers upon request.

Case Studies

Case Studies

Download one-pagers, case studies, and white papers to learn how Lukka supports institutional data, pricing, compliance, analytics, and reporting workflows across digital assets.

White Papers

What is the scope of a SOC 2 report?

Per the AICPA, SOC 2 reports cover controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy. These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to security, availability, and processing integrity of the systems the service organization uses to process users’ data and the confidentiality and privacy of the information processed by these systems.

These reports can play an important role in: 

  • Oversight of the organization
  • Vendor management programs
  • Internal corporate governance and risk management processes
  • Regulatory oversight

Are all SOC 2 audits the same?

No, they are all custom-tailored to the specific Service Organization and can vary significantly. SOC 2 reports specifically may or may not include any of the 5 risk domain areas: Security, Availability, Processing Integrity, Confidentiality, and Privacy. We recommend asking any Service Organization that you plan on using as a vendor who their SOC auditor is, for a copy of the SOC report, whether it was a Type I or Type II (Type II is strongly preferred), and how many years the Service Organization has conducted SOC audits.

What time period is associated with Lukka’s Type II audits?

Lukka conducts both SOC 1 Type II and SOC 2 Type II audits annually. For the portion of the year outside of testing periods, we offer bridge letters to customers upon request.