1. The short version
cybersoftware is SOC 2 compliance software, built by a small team. The readiness assessment is free. The software is one plan you pay monthly or yearly, and monthly can be cancelled any time. Audits go through our preferred pricing program, and you see the price of an audit in your account before you book it. You always own your data, and reports we issue stay yours. Below is the legal version of those promises.
2. Who you're agreeing with
"cybersoftware" or "we" / "us" / "our" means cybersoftware, a company organized in the United States. "You" or "your" means the person or business entity that signs up for an account at cybersoftware.com. By creating an account, paying for a cybersoftware service, or otherwise using the platform, you agree to these terms.
3. What the service is
cybersoftware provides software, content, and process management to help your company prepare for, complete, and maintain a SOC 2 examination. This includes intake assessment, deterministic gap identification, AI-generated policies and documentation, evidence collection workflow, report generation, and coordination with an independent U.S. CPA firm engaged to perform the examination. The platform is hosted, browser-based, and currently English-only.
cybersoftware is not a CPA firm and does not perform the SOC 2 examination itself. The audit opinion is issued by the independent CPA firm assigned to your engagement. We act as a technology provider and project coordinator.
4. Pricing and payment
Pricing is published at cybersoftware.com/#pricing. The clauses below state the model as of the date of these terms. All prices are in USD.
a. Free. The readiness assessment, your score, your results and gap list, and one AI written sample policy cost nothing and need no card.
b. Software, monthly. $199 per month, covering SOC 2. You can cancel any time. Cancelling takes effect at the end of the month you have paid for, and there is no charge after that.
c. Software, yearly. $2,189 per year for the same software, paid up front. It renews each year unless you cancel. Cancelling takes effect at the end of the paid year.
d. What the plan covers. A software plan, monthly or yearly, covers SOC 2, Type 1 and Type 2. cybersoftware does not offer ISO 27001 or any other framework. Access ends when your plan ends.
e. Audits go through our preferred pricing program. We negotiate audit fees on your behalf with an independent partner auditor, a licensed U.S. CPA firm. The price of every audit, SOC 2 Type 1 and SOC 2 Type 2, is shown to you in writing inside your account before you book it. You owe nothing for an audit until you book and pay for it.
f. When you can book an audit. On the monthly plan, after 4 paid months. On the yearly plan, right away. The same rule applies to exporting your audit package to an auditor you choose yourself. A SOC 2 Type 2 audit also needs the 3 month observation window to be complete.
g. Your price is locked while you stay subscribed. If we change our prices, your plan keeps the price you signed up at for as long as it stays active. If your plan ends and you start again later, the price at that time applies.
h. What happens when a plan ends. When a software plan is cancelled, it runs to the end of the period you have paid for, and then your workspace returns to the free plan. Paid features stop: check-ins, connectors, AI written policies, audit requests and trust monitoring. Every report already issued, and your downloads, stay yours forever, and public verification of an issued report stays live.
i. Failed payments. Payments are collected by Stripe. If a recurring payment fails, you have a seven day grace period during which your plan stays available. After that, paid features pause until your payment method is updated.
5. Refunds
Refund eligibility, request process, and timing are described in our Refund Policy, which is incorporated into these terms by reference.
6. Your account and conduct
You are responsible for keeping your account credentials secure, providing accurate information during intake, and ensuring that any team members granted access to your engagement are authorized to act on your behalf. You agree not to use cybersoftware to misrepresent the security posture of your company, fabricate evidence, or otherwise undermine the integrity of the SOC 2 examination. We may suspend or terminate access to any account engaged in such conduct.
7. Auditor independence
AICPA professional standards require that the CPA firm performing your SOC 2 examination remain structurally independent from cybersoftware. Your examination is performed by an independent partner auditor, a licensed U.S. CPA firm. cybersoftware does not draft audit conclusions, does not influence findings, does not share equity, fees, or referral compensation with any auditor in our network, and holds no financial interest in the outcome of your examination. The specific firm assigned to your engagement is disclosed to you on request before you sign the engagement letter. See our Independence and Ethics page for the full architectural commitment.
8. Your data
All evidence files, policy drafts, intake responses, and audit artifacts you submit to cybersoftware remain your property. We process this data solely to deliver the service: generate policies tied to your specific environment, surface gaps, map evidence to controls, and prepare the package the auditor reviews. We do not sell your data, train AI models on your data, or use your data to benefit other customers.
Evidence files are stored encrypted in AWS S3 with access restricted by signed URLs available only to you and your assigned auditor. Backend logging is limited to operational telemetry (no body content). You may export or delete your data at any time by emailing surya@cybersoftware.com; we honor export requests within 30 days and delete requests within 60 days, subject to legal retention obligations.
9. AI-generated content
cybersoftware uses large language models (currently AWS Bedrock with Anthropic Claude) to draft policies, gap remediation guidance, and report narrative tied to your intake answers and evidence. AI output is generated from your data, not templates with your name swapped in, and is grounded in evidence you provide. But it is not infallible. You and your assigned auditor are the final reviewers. You agree to review every generated policy before it is delivered to your auditor, and you accept responsibility for the controls actually implemented in your environment.
10. Service availability and changes
We aim for high availability but do not guarantee uninterrupted service. We may add, modify, or discontinue features without prior notice. Material changes that affect an active engagement (such as removing a feature you depend on mid-audit) will be announced by email at least 14 days in advance.
11. Intellectual property
The cybersoftware platform, including software, design, brand assets, and proprietary algorithms, is owned by cybersoftware. We grant you a non-exclusive, non-transferable license to use the platform for the purpose of obtaining a SOC 2 examination of your own company while your plan is active. Generated policies become your property once delivered, and you may use, modify, or republish them as your own internal documents.
12. Disclaimers
cybersoftware is provided "as is" and "as available" without warranties of any kind, express or implied, including warranties of merchantability, fitness for a particular purpose, accuracy, or non-infringement. We do not warrant that the SOC 2 examination will result in a clean opinion, that your customers will accept the report for their security review, or that any specific gap will be remediated by use of the platform alone. Audit outcomes depend on the controls you actually implement and operate.
13. Limitation of liability
To the maximum extent permitted by law, cybersoftware's total liability arising out of or related to these terms or your use of the service is limited to the amount you paid cybersoftware in the twelve months preceding the claim. We are not liable for indirect, incidental, special, consequential, or punitive damages, including lost revenue, lost customers, or reputational harm, even if advised of the possibility of such damages. Some jurisdictions do not allow this limitation; in those jurisdictions our liability is limited to the maximum extent permitted by applicable law.
14. Indemnification
You agree to defend and indemnify cybersoftware and its officers, employees, and contractors from any third-party claims, damages, or expenses (including reasonable attorneys' fees) arising from (a) your misuse of the platform, (b) your violation of these terms, or (c) any false or misleading information you provided during intake or evidence collection that contributed to a flawed audit outcome.
15. Termination
You may stop using cybersoftware at any time by closing your account. We may suspend or terminate access for material breach of these terms, suspected fraud, or non-payment after notice and opportunity to cure. Upon termination, your right to use the platform ends, but your data export rights, our confidentiality obligations, and the limitation-of- liability and indemnification clauses survive.
16. Governing law and disputes
These terms are governed by the laws of the State of Delaware, United States, without regard to conflict-of-law provisions. Any dispute that cannot be resolved informally will be resolved by binding arbitration administered by JAMS in San Francisco, California, except that either party may bring an action in small-claims court for claims within that court's jurisdiction. You waive your right to participate in a class action against cybersoftware.
17. Changes to these terms
We may update these terms when product, legal, or business circumstances change. The "Last updated" date at the top reflects the most recent change. Material changes will be announced by email to active customers at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.
18. Contact
Questions, concerns, or legal notices should go to surya@cybersoftware.com. We respond to legal correspondence within 5 business days.
Plain-English footnote: we are a small startup. We genuinely want you to succeed at SOC 2, not to wrap you in legalese. If anything in here surprises you or seems unfair, email us. We will read it and probably change it. The cybersoftware team.