What compliance reports and certifications does Colo Solutions have?
Colo Solutions holds unqualified SOC 1 Type 2 and SOC 2 Type 2 reports for its Orlando colocation facility, both covering October 1, 2024 through September 30, 2025 and both examined by 360 Advanced. An independent HIPAA Security Compliance Assessment was completed as of September 30, 2025, and BAAs are executed routinely. Colo Solutions holds no PCI DSS attestation and is not a payment processor; the facility's physical access controls supporting PCI DSS Requirement 9 are covered by the SOC 2.
| SOC 1 Type 2 | Colocation Services, Oct 1 2024 – Sep 30 2025, unqualified — 360 Advanced, Inc. |
|---|---|
| SOC 2 Type 2 | Security and Availability, Oct 1 2024 – Sep 30 2025, unqualified — 360 Advanced, Inc. |
| HIPAA | Security Compliance Assessment, results as of Sep 30 2025 — 360 Advanced, Inc. |
| BAAs | Executed routinely |
| PCI DSS | No attestation held; Requirement 9 physical controls covered by the SOC 2 |
The short version
Three independent engagements, all performed by 360 Advanced, Inc. of St. Petersburg, Florida. Each is described below with what it does and does not cover, because the differences matter more than the logos.
SOC 1 Type 2 and SOC 2 Type 2
Both cover the Colocation Services system for October 1, 2024 through September 30, 2025, and both carry unqualified opinions — the auditor’s conclusion, in all material respects, that the description was fair, the controls were suitably designed, and they operated effectively across the period.
SOC 1 addresses controls relevant to user entities’ internal control over financial reporting. SOC 2 addresses the Security and Availability trust services criteria — two of the five categories.
HIPAA Security Compliance Assessment
360 Advanced completed an independent assessment of controls in place for the Colocation Services, scoped to the aspects of the HIPAA Security Final Rule relevant to Colo Solutions as a potential business associate. Results were delivered as of September 30, 2025.
This is a point-in-time assessment, not a period examination — it speaks to controls as designed and implemented on that date, and it is not interchangeable with the SOC reports’ “operated effectively throughout” conclusion. There is also no such thing as HIPAA certification; any vendor claiming it is describing something that does not exist.
Business Associate Agreements are executed routinely.
PCI DSS
Colo Solutions holds no PCI DSS attestation, and does not claim one. We are not a payment processor: customers pay by business check or through their own Intuit account, so cardholder data does not reach us in the ordinary course of business.
That is usually the wrong question anyway. If your own cardholder data environment is hosted in a cabinet here, what you need from the facility is PCI DSS Requirement 9 — restricting physical access to cardholder data. Dual factor access at every door, a mantrap, uniquely keyed cabinets, recorded video with 90-day retention and access records all speak to that requirement, and they are in scope of the SOC 2 Type 2 examination. For your assessor, an examined control is better evidence than a provider’s self-assessment.
The rest of PCI scope — your systems, segmentation, key management and logging — remains yours to validate.
Bridge letters and copies
The engagement year runs to 30 September, with reports issued in the following months. Bridge letters covering the interval — confirming no material change to controls since the end of the reported period — are available on request.
All reports are restricted-use documents and are provided under NDA. Call (407) 210-2480.