uable.store · First review · Mac / Linux · vs Knapsack
You asked what SOC 2 is. It is not a feature we can switch on. It is homework.
SOC 2 is a letter from an outside auditor that says: this company wrote security rules, and (for Type 2) actually followed them for several months. Banks and hospitals ask for it before they put data in someone else's cloud.
Type 1 = “you have a rulebook.” Type 2 = “you lived by it for ~3–12 months.” Vanta and Drata are software that collect screenshots and tickets for the auditor. They are not the certificate. The auditor is. That costs real money and calendar time. Knapsack did that because they hold firm data in a cloud studio.
Able’s vault is designed to stay on your Windows PC. An Apex SOC 2 letter, when we have one, would cover the store, fuel pipe, and updates — not your vault. We have not started that program. We will not draw a badge.
| Thing | Truth |
|---|---|
| SOC 2 Type 1 / Type 2 | Not started. No auditor. No badge. |
| HIPAA / ISO | Not claimed. |
| Customer case study | None yet. Operator review only: /reviews |
| Windows EV code signing | In progress. SmartScreen may warn. |
| Septaguard vault | On this PC. AES-256-GCM + Argon2. Cloud brains never get the vault password. |
| Stripe | Live. Cards stay with Stripe. |
| OTA + signed modules | Live from api.uable.store |