# What compliance reports and certifications does Colo Solutions have?

Source: https://www.colosolutions.com/answers/what-compliance-does-colo-solutions-have/
Updated: 2026-08-27
Reviewed by: James San Filippo

Colo Solutions holds unqualified SOC 1 Type 2 and SOC 2 Type 2 reports for its Orlando colocation facility, both covering October 1, 2024 through September 30, 2025 and both examined by 360 Advanced. An independent HIPAA Security Compliance Assessment was completed as of September 30, 2025, and BAAs are executed routinely. Colo Solutions holds no PCI DSS attestation and is not a payment processor; the facility's physical access controls supporting PCI DSS Requirement 9 are covered by the SOC 2.

## Key figures

- **SOC 1 Type 2:** Colocation Services, Oct 1 2024 – Sep 30 2025, unqualified (360 Advanced, Inc.)
- **SOC 2 Type 2:** Security and Availability, Oct 1 2024 – Sep 30 2025, unqualified (360 Advanced, Inc.)
- **HIPAA:** Security Compliance Assessment, results as of Sep 30 2025 (360 Advanced, Inc.)
- **BAAs:** Executed routinely
- **PCI DSS:** No attestation held; Requirement 9 physical controls covered by the SOC 2

## The short version

Three independent engagements, all performed by 360 Advanced, Inc. of St.
Petersburg, Florida. Each is described below with what
it does and does not cover, because the differences matter more than the logos.

## SOC 1 Type 2 and SOC 2 Type 2

Both cover the Colocation Services system for **October 1, 2024 through September
30, 2025**, and both carry **unqualified opinions** — the auditor's conclusion,
in all material respects, that the description was fair, the controls were
suitably designed, and they operated effectively across the period.

SOC 1 addresses controls relevant to user entities' internal control over
financial reporting. SOC 2 addresses the **Security and Availability** trust
services criteria — two of the five categories.

## HIPAA Security Compliance Assessment

360 Advanced completed an independent assessment of controls in place for the
Colocation Services, scoped to the aspects of the HIPAA Security Final Rule
relevant to Colo Solutions as a potential business associate. **Results were
delivered as of September 30, 2025.**

This is a point-in-time assessment, not a period examination — it speaks to
controls as designed and implemented on that date, and it is not interchangeable
with the SOC reports' "operated effectively throughout" conclusion. There is also
no such thing as HIPAA certification; any vendor claiming it is describing
something that does not exist.

Business Associate Agreements are executed routinely.

## PCI DSS

**Colo Solutions holds no PCI DSS attestation, and does not claim one.** We are
not a payment processor: customers pay by business check or through their own
Intuit account, so cardholder data does not reach us in the ordinary course of
business.

That is usually the wrong question anyway. If your own cardholder data
environment is hosted in a cabinet here, what you need from the facility is PCI
DSS **Requirement 9** — restricting physical access to cardholder data. Dual
factor access at every door, a mantrap, uniquely keyed cabinets, recorded video
with 90-day retention and access records all speak to that requirement, and they
are in scope of the SOC 2 Type 2 examination. For your assessor, an examined
control is better evidence than a provider's self-assessment.

The rest of PCI scope — your systems, segmentation, key management and logging —
remains yours to validate.

## Bridge letters and copies

The engagement year runs to 30 September, with reports issued in the following
months. **Bridge letters** covering the interval — confirming no material change
to controls since the end of the reported period — are available on request.

All reports are restricted-use documents and are provided under NDA. Call
(407) 210-2480.