Checklist progress
0/168Learned
Heroku Architect
Study Checklist
Checklist progress
0/168Learned
Construct architectures that leverage Heroku to achieve different security certifications.
0/7
What is the difference between SOC 1 and SOC 2 compliance on Heroku?
Learn this conceptWhich Heroku runtime and plan tier is required to host applications that must comply with HIPAA?
Learn this conceptRecommend Heroku Private Space Peering or VPN connections for appropriate use cases.
0/6
Recommend when an app should run in the Private Space Runtime versus the Common Runtime.
0/7
Prepare for the Exam
Study Community
Ask questions and get the latest info from other Heroku Architect studiers. 593 members and growing.
SOC 1 and SOC 2 are independent audit reports that differ in scope: SOC 1 (Type II) covers IT general controls relevant to customers' financial reporting, while SOC 2 (Type 2) evaluates controls around security, availability, and confidentiality of the Heroku Platform. Heroku holds both reports, meaning an architect can match the appropriate report to an enterprise customer's compliance need—financial auditors require SOC 1, while security and procurement teams typically require SOC 2.