Skip to main content
S

Author

Solomon Amos

Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

Aboutsolomonamos.comLinkedIn

Articles by Solomon Amos

Explainers

There is no such thing as "SOC 2 certified"

SOC 2 is an attestation report with an opinion, a period and an auditor. Nobody issues a certificate. What the phrase hides, why it spreads, and the four facts to ask for instead.

Solomon Amos · 15 Sep 2026 · 9 min read

Explainers

SOC 2 Type I vs Type II: what each one proves to a buyer

Type I says controls were designed properly on one date. Type II says they operated over a period with sampled evidence and listed exceptions. Which to accept, when, and what to ask.

Solomon Amos · 14 Sep 2026 · 10 min read

How-to

How to read a SOC 2 report in 20 minutes

A section-by-section reading order for buyers: the opinion, Type and period, criteria in scope, carve-outs, exceptions and the controls you must run yourself.

Solomon Amos · 11 Sep 2026 · 11 min read

How-to

How to read a trust centre in ten minutes

Vanta, Drata and SafeBase trust centres all look alike. What each section actually proves, which badges are claims, what freshness signals matter, and how to get the facts out without requesting access.

Solomon Amos · 10 Sep 2026 · 10 min read

How-to

A 30-minute vendor security review using public evidence

The questions to answer before you email sales, in the order that saves the most time: registries first, vendor statements second, questionnaires last. With the numbers on why.

Solomon Amos · 30 Aug 2026 · 11 min read