Compliance

What we are examined against, and what that does not cover

Colo Solutions is examined annually by 360 Advanced, Inc. Below is each report, its exact scope and period, and — the part that usually matters more — the line where our responsibility ends and yours begins. Reports are restricted-use and provided under NDA.

The reports

Current attestations and their scope
SOC 2 Type 2 Security and Availability trust services criteria, for the Colocation Services system. Covers October 1, 2024 through September 30, 2025 — controls operated effectively throughout the period. Unqualified opinion. — 360 Advanced, Inc.
SOC 1 Type 2 Controls relevant to user entities’ internal control over financial reporting, for the Colocation Services system. Covers October 1, 2024 through September 30, 2025. Unqualified opinion. — 360 Advanced, Inc.
HIPAA Security Rule Examination of controls against the HIPAA Security Final Rule, for the Colocation Services system. A point-in-time examination: controls were designed and implemented as of September 30, 2025. — 360 Advanced, Inc.

A note on wording, because it is routinely blurred: SOC 1 and SOC 2 are examinations that produce reports, not certifications, and there is no such thing as HIPAA certification from any body. If a provider tells you they are “SOC 2 certified”, they are telling you something about how carefully they read their own report.

Two things the SOC 2 does not cover

Three of the five trust services categories are out of scope. The examination covers Security and Availability. It does not cover Confidentiality, Processing Integrity or Privacy. “SOC 2” unqualified is widely read as all five, so if your risk review assumes Confidentiality is in scope, it is not — ask us and we will say so.

Certain criteria were deemed not applicable, deliberately. Colo Solutions does not have logical access to customer environments, does not manage or monitor customer infrastructure, and does not develop or manage changes to customer systems. For a colocation provider that is a feature, not a gap: your environment stays yours, and the boundary is documented in an examined report rather than asserted in marketing.

PCI, and why we do not claim it

We are not a payment processor. Customers pay by business check, or through Intuit using their own account and their own card — which means cardholder data does not reach Colo Solutions in the ordinary course of business. We hold no PCI DSS attestation and we do not claim one. Any provider in our position telling you they are “PCI compliant” is worth a second question.

The question worth asking is the other one. If your own cardholder data environment is going to live in a cabinet here, what you need from a colocation provider is PCI DSS Requirement 9 — restricting physical access to cardholder data. That is precisely what this facility supplies: dual-factor access at every door, a mantrap at the entrance, uniquely keyed cabinets, recorded video with 90-day retention, and access records. Those controls are in scope of the SOC 2 Type 2 examination above, which is stronger and more useful evidence for your assessor than a self-assessment would be.

Everything else in PCI scope — your systems, your network segmentation, your key management, your logging — remains yours, exactly as set out in the boundary below.

Where our responsibility ends and yours begins

The SOC 2 description states that customer-side controls are necessary, alongside ours, to achieve the service commitments — complementary user entity controls. Your auditors will ask for this boundary, so here it is in plain language rather than as an appendix.

Ours

  • Physical access to the building, the floor and your cabinet or cage
  • Environmental controls — power, cooling, fire detection and suppression
  • Video surveillance and access records
  • Availability of critical infrastructure per the SLA
  • Screening of our own personnel

Yours

  • Everything running on your equipment — operating systems, applications, data
  • Logical access control, credentials and encryption for your systems
  • Patching, vulnerability management and change control on your infrastructure
  • Backup and recovery of your data, unless you have separately bought it from us
  • Deciding who on your side is authorized for facility access, and telling us when that changes

This is also the cleanest way to understand the difference between Colo Solutions and a managed IT provider. We are responsible for the facility your equipment lives in. If you want someone accountable for what runs on it, that is a separate engagement with a separate provider — and it cannot ride on this report.

HIPAA, specifically

The HIPAA engagement is an examination of controls against the HIPAA Security Final Rule, performed by 360 Advanced, Inc. alongside the SOC 2, scoped to Colocation Services. It is point-in-time: controls were designed and implemented as of September 30, 2025. It is not a certification, and it does not make your use of the facility HIPAA-compliant on its own — your own safeguards on your own systems still have to be there.

We execute Business Associate Agreements, routinely. That is usually the first question a healthcare prospect asks, and the answer is a straight yes.

More on BAAs →

Getting the reports, and covering the gap

All reports are restricted-use. We can share the existence, type, scope, period, examiner and outcome publicly — this page — but the reports themselves go out under NDA. Ask and we will send the current set.

The 2025–2026 engagement is in progress and expected to finalise in September 2026. Until it does, we issue bridge letters covering the period since the end of the most recent report, confirming no material change to controls. If your vendor-risk process needs one, ask — it is a routine request and we will not have to go away and find out.

Request the reports under NDA Short version