Vendor reviews usually call for the vendor's own SOC 2 report or equivalent certification as evidence — see Managing Vendors & Conducting Vendor Reviews. Before emailing a vendor's support team to ask for one, check whether they already publish it.
Check for a trust portal first
Most established SaaS and cloud vendors maintain a public trust center or trust portal — search "[vendor name] trust center" or "[vendor name] security" and you'll usually land on it directly. These typically list current certifications (SOC 2, ISO 27001, and similar) and let you either download the report immediately or submit a quick self-serve request that emails it to you — often faster than reaching out to support directly.
Larger cloud providers (AWS, Microsoft Azure, Google Cloud) also run dedicated compliance-document programs of their own, usually requiring you to log into an account under an NDA before downloading — a heavier process than a typical vendor's trust portal, but still self-serve.
If you can't find one
Some vendors, especially smaller ones, don't have a public trust portal. In that case, asking their sales or support team directly for their most recent SOC 2 report (or pointing them to your own Trust Center as a "send us yours, here's ours" gesture) is the normal path.
Whatever you get back, upload it as evidence on the vendor's record in your own Vendor Register.
If the vendor's report is locked behind an enterprise tier
Some vendors only release their SOC 2 report to customers on an enterprise plan, and won't share it with a smaller account no matter how you ask. This is common enough that auditors generally accept alternative evidence instead — most often:
The vendor's own public security page (most vendors publish a summary of their controls even without a full report), plus
A self-filled vendor questionnaire — CAIQ-Lite (Consensus Assessments Initiative Questionnaire) or SIG-Lite are the two standard, widely-recognized formats — completed based on the vendor's public documentation and your own knowledge of how you use them.
Document why the full report wasn't available (gated behind a tier you're not on) alongside whatever alternative evidence you did gather — auditors want to see the reasoning, not just the substitute document. This combination is a legitimate, commonly-accepted answer, not a workaround to apologize for.
When someone asks you for your SOC 2 report as a vendor
If another company is reviewing ComplyJet (or you) as one of their vendors, the same logic runs in reverse — point them to your own Trust Center rather than emailing a PDF ad hoc. It's the same self-serve mechanism you'd want from your own vendors, and it means you only have to keep one place up to date.
