Genio (formerly Glean) successfully completes a SOC 2® assessment
This blog outlines what a SOC 2 report is and what it means for Genio.


At Genio, we continually invest in security best practices to ensure that our customer data stays safe and secure. As a part of an ongoing effort, we are excited to announce that we’ve successfully completed our SOC 2 assessment!
The examination was conducted by A-LIGN, a technology-enabled security and compliance firm trusted by more than 2,500 global organizations to help mitigate cybersecurity risks. A-LIGN did an incredibly thorough evaluation of our operations: they interviewed employees, observed processes, inspected documentation, and much more.
So, what is a SOC 2 report and what does it mean for Genio? In this article, we will walk you through the ins and outs of a SOC 2 report and how the report symbolizes trust to customers.
What is a SOC 2 report?
A SOC 2 report addresses risks associated with the handling and access of data, and can be used by a variety of organizations of any size (e.g. SaaS, colocation, data hosting, etc.) Rather than a cybersecurity assessment that evaluates specific technical configurations, a SOC 2 report focuses more on how an organization implements and manages controls to mitigate the identified risks to the different parts of an organization.
The SOC 2 audit testing framework is based on the Trust Services Criteria (TSC), which are used to identify various risks (points of focus) an organization should consider addressing. Based on the TSCs the organization selects to be in-scope, the third-party compliance and audit firm (in our case, A-LIGN) evaluates whether the organization has the appropriate policies, procedures and controls in place to manage the identified risks effectively.
There are five Trust Services Criteria. The first criteria, Security, must be included with every SOC 2 report and is referred to as the “Common Criteria”. The remaining four are optional to include:
- Security (required)
- Availability (optional)
- Processing Integrity (optional)
- Confidentiality (optional)
- Privacy (optional)
In order to pass a SOC 2 examination and receive a letter of attestation successfully, it means an organization is addressing controls in areas such as information security, access control, vendor management, system backup, business continuity and disaster relief, and more.
Genio was audited on the Security Trust Services Criteria.
Why do we need SOC 2?
With one of our core values being trust, we knew that completing a SOC 2 was imperative. Today, many organizations outsource their business operations and services to third-party vendors, possibly putting client data at risk. For this reason, organizations request that their vendors achieve SOC 2 compliance to demonstrate rigorous IT security standards.
Know your data is safe and secure with Genio
Genio will happily make the SOC 2 report available to current or potential customers upon execution of a non-disclosure agreement.
We hope the steps we have taken help you and your IT teams remain confident in knowing that your data is secure with Genio!
To learn more about our security policies and initiatives, please see www.glean.co/security
More from Genio News
View All
Student confidence increases by 84% in pre-launch testing after completing The Confident Notetaker's Masterclass
Before launching our first online course, The Confident Notetaker's Masterclass, we ensured in depth testing and research took place, to ensure it was carefully crafted to address challenges faced by students. Here, we take a look at the research and findings that took place behind the scenes.

Rebranding to Genio: The journey to unlock better learning
We're excited to announce that Glean is now Genio, with more for learners than ever before! Join us as we step into this new chapter, dedicated to unlocking better learning for everyone.

Goodbye Glean, Hello Genio
Glean rebrands as Genio, launches The Confident Notetaker’s Masterclass and Genio Present, our new presentation support tool.