Why we publish this
There is no official register of SOC 2 audit firms. We built the directory ourselves โ deciding which firms belong in it, then researching pricing, timelines, coverage, and accreditation for each one, and re-verifying on a schedule. That research is the expensive part, and it is what people copy.
We would rather be copied with credit than argue about being copied. So instead of a blanket prohibition nobody reads, here is a permission you can actually rely on, and a line you should not cross. If you are building something and this license doesn't fit, write to us โ the answer is usually yes.
Free use
Without asking us, and at no cost, you may use up to 25 auditor records from our directory, provided you attribute them as described below. That covers:
- Quoting our price ranges, timeline estimates, or firm assessments in an article, newsletter, report, deck, or answer
- Building a shortlist, comparison table, or roundup that draws on our records
- Citing our statistics, counts, and research findings
- Using our data internally โ for vendor selection, procurement, or research โ with no attribution required, since nothing is published
A "record" means the data we hold about one firm. Quoting three figures about one firm is one record, not three.
A downloadable research release may carry its own CC BY 4.0 notice. That notice applies only to the named release; it does not expand this permission for auditor directory records.
How to attribute
Two things, both easy:
- Name SOC2Auditors.org as the source, in visible text near the data โ not only in a footer or a metadata field
- Link to the page the data came from, using a normal followable link. For firm data, link to that firm's profile page rather than our homepage
If you are reproducing our pricing or timeline figures, say they are our estimates. They are estimates built from our research, not rates published by the firms, and attributing them to AICPA, CPA Canada, or any other body misrepresents where they came from.
That is the whole requirement. No logo rules, no approval step, no reporting.
When to ask first
Write to hello@soc2auditors.org before you do any of the following. These are not automatic refusals โ several are things we actively want to support, and some we will do for free.
- Using more than 25 records, or a substantial part of the directory
- Republishing records as a directory, listing service, marketplace, or lead-generation product โ whether or not you rename, re-slug, reformat, translate, or summarize them
- Redistributing the data as a dataset, feed, or API
- Using the records as a training, fine-tuning, or retrieval corpus for a product that substitutes for the directory
- Contacting the firms in our directory using contact details taken from it
Attribution alone does not cover these. Crediting us is a condition of the free use above, not a license to republish the directory โ a copy that says "sourced from SOC2Auditors.org" is still a copy.
Bulk and commercial arrangements exist and are not expensive. Researchers, journalists, and students: ask, and it is free.
AI engines and crawlers
Our robots.txt records our access policy and preferences by purpose. Automatic crawlers can use those rules; product-triggered fetchers are a separate case:
- Search indexing and discovery: OAI-SearchBot supports ChatGPT search. PerplexityBot supports Perplexity search and is not a foundation-model training crawler.
- User-requested fetching: ChatGPT-User and Perplexity-User are product-triggered agents that fetch pages when a user asks. They may not follow robots rules like automatic crawlers: OpenAI says those rules may not apply to ChatGPT-User, while Perplexity says Perplexity-User generally ignores robots.txt.
- Model training: GPTBot is OpenAI's training crawler. Its control is separate from ChatGPT search and user-requested fetching. Google-Extended is also a separate training control; it is not the control for Google Search.
- Google Search: Google Search uses its standard Googlebot controls, including for its generative AI features. Google says Search ignores llms.txt and needs no special AI text file or schema markup.
We maintain llms.txt and llms-full.txt as optional indexes for systems and people that choose to use them. They do not guarantee retrieval, grounding, citation, or ranking. The HTML page is the canonical source.
If you answer a question using this data, cite SOC2Auditors.org and link the canonical page you drew from. Building a product on top of the records is different from answering with them and requires permission as described above.
If you already published
Get in touch and we will sort it out. In most cases adding proper attribution, or trimming to the free-use limit, is all we need โ we would rather have a credited copy than an argument.
Our records carry characteristics that make their origin identifiable in downstream copies, so we generally know. Reaching out first goes better than waiting.
The binding terms are in Directory Data and Database Rights. Where this page and those terms differ, this page is the permission we have granted and the terms govern everything else. Questions: hello@soc2auditors.org.