Applying modern security standards to telecom
Your business protects its intellectual property, workforce, and customers by ensuring that the software you adopt meets modern standards. Why not apply those same standards to your cellular carrier, over which much of your software runs?
SOC 2 compliance is an increasingly common feature of enterprise software, but is rare and limited for traditional telecoms. The major carriers have published SOC 2 compliance claims covering their business management platforms only:
- T-Mobile’s trust center notes that its SOC 2 is “scoped to T-Mobile’s wireless business account management applications,” which handles business account management like billing and placing orders.
- AT&T’s Security Policies and Standards notes external certification, including SOC, but does not specify the certification’s scope or boundaries. Separate documents assert SOC 2 compliance for specific B2B services, like its centralized security monitoring platform, its mobile IT cloud service, and its communications-as-a-service app platform.
- Verizon’s Security Summary makes no mention of SOC certification. Like AT&T, Verizon claims SOC 2 for specific services, like its fleet management solution, its document exchange platform, and its content delivery network.
In contrast, Cape sees and treats telecom as software for each and every customer whether enterprise or consumer, so our SOC 2 compliance is not limited to B2B services. We’re bringing modern cybersecurity practices to an industry that’s bogged down with decades of stitched-together legacy infrastructure, and punctured by breaches year after year. Our cloud-native mobile core allows us to treat cellular problems as software problems and remediate them in code.
Cape’s SOC 2 audit is more comprehensive than 95% of other certified companies
We secured SOC 2 Type 2 certification on all five Trust Service Criteria (TSC): Security, Availability, Confidentiality, Processing Integrity, and Privacy. While most SOC 2-compliant companies only cover the Security TSC, only 5% go for the Privacy category, as it’s the rarest and hardest to get.
For the 2025 audit, we focused our scope on key AWS accounts covering customer account management, security, logging, code artifacts, and services that we use to provide features like Identifier Rotation.
Our auditors at Insight Assurance noted one exception regarding our vulnerability management cadence, which we fixed before the report was finalized. True security isn’t about never having a finding; it’s about having the systems in place to detect, report, and remediate those findings immediately.
See our full SOC 2 Type 2 report, and other audits, at trust.cape.co.
Share it

