← Back to Index
Delve Tech Due Diligence · Meta-Analysis

Executive Overview

Portfolio-wide summary of 485 SOC 2 compliance reports

485
Companies Analyzed
5.6/10
Average Score
19
Score 7+ (High)
59%
AWS Adoption
44%
WAF Adoption
28%
Multi-Region

Score Distribution

Across 121 scored companies, the average tech DD score is 5.6/10 (median: 6). The distribution clusters tightly at 5-6, with 19 companies (16%) scoring 7+ and 12 (10%) scoring 4 or below.

score_distribution.png

N=121 companies with dimension scores

Key insight: The tight clustering at 5-6/10 suggests most companies achieve a similar baseline from template-driven SOC 2 compliance. The differentiators that push a company to 7+ are specific: multi-region deployment, WAF, named monitoring tools, and vendor transparency.

Dimension Analysis

Security is the strongest dimension (6.9/10) — MFA, RBAC, and basic firewalls are near-universal. Vendor Diversity is the weakest (4.3/10) — most companies depend on a single cloud provider with minimal third-party disclosure.

dimension_averages.png

Error bars show standard deviation

Dimension Ranking

DimensionMeanMedianStdMinMax
Infrastructure6.061.038
App Arch5.151.429
Data Layer5.051.338
Security6.970.759
DevOps5.660.948
BCDR5.960.748
Vendor Div4.341.829

Security & Infrastructure Adoption

The portfolio shows a clear three-tier security maturity pattern:

feature_adoption.png

N=485 companies

Cloud Provider Landscape

AWS dominates at 59%, creating systemic portfolio-level concentration risk. A major AWS outage would simultaneously impact over half the portfolio.

cloud_distribution.png

Key Takeaways

For PE: 28% multi-region adoption means 72% of the portfolio has single-region risk. Migrating companies to multi-region is a concrete value creation lever.
For VC: Vendor transparency (naming 5+ third-party services) correlates with higher scores. Ask founders to name their full stack — opacity is a red flag.
For CTO: Security (6.9/10) outpaces DevOps (5.6/10). Most companies have security controls but lack CI/CD maturity.
score_distribution.png
dimension_averages.png
feature_adoption.png
cloud_distribution.png

Generated from executive overview module · 485 SOC 2 compliance reports · 2026-03-24