Ingka Group acquires Locus! Built for the real world, backed for the long run. Read here>Read the full story>
Ingka Group acquires Locus! Built for the real world, backed for the long run. Read the full story
locus-logo-dark
Schedule a demo
Locus Logo Locus Logo
  • Platform
    • Transportation Management System
    • Last Mile Delivery Solution
  • Products
    • Fulfillment Automation
      • Order Management
      • Delivery Linked Checkout
    • Dispatch Planning
      • Hub Operations
      • Capacity Management
      • Route Planning
    • Delivery Orchestration
      • Transporter Management
      • ShipFlex
    • Track and Trace
      • Driver Companion App
      • Control Tower
      • Tracking Page
    • Analytics and Insights
      • Business Insights
      • Location Analytics
  • Industries
    • Retail
    • FMCG/CPG
    • 3PL & CEP
    • Big & Bulky
    • Other Industries
      • E-commerce
      • E-grocery
      • Industrial Services
      • Manufacturing
      • Home Services
  • Resources
    • Guides
      • Reducing Cart Abandonment
      • Reducing WISMO Calls
      • Logistics Trends 2024
      • Unit Economics in All-mile
      • Last Mile Delivery Logistics
      • Last Mile Delivery Trends
      • Time Under the Roof
      • Peak Shipping Season
      • Electronic Products
      • Fleet Management
      • Healthcare Logistics
      • Transport Management System
      • E-commerce Logistics
      • Direct Store Delivery
      • Logistics Route Planner Guide
    • ROI Calculator
    • Product Demos
    • Whitepaper
    • Case Studies
    • Infographics
    • E-books
    • Blogs
    • Events & Webinars
    • Videos
    • API Reference Docs
    • Glossary
  • Company
    • About Us
    • Global Presence
      • Locus in Americas
      • Locus in Asia Pacific
      • Locus in the Middle East
    • Analyst Recognition
    • Careers
    • News & Press
    • Trust & Security
    • Contact Us
  • Customers
en  
en - English
id - Bahasa
Schedule a demo
  1. Home
  2. Blog
  3. Enterprise SLAs, SOC 2 and 24/7 Support: How to Verify TMS Vendor Claims

General

Enterprise SLAs, SOC 2 and 24/7 Support: How to Verify TMS Vendor Claims

Avatar photo

Ishan Bhattacharya

Sep 7, 2026

15 mins read

Enterprise assurance in a TMS procurement covers three separate things that are usually discussed as one: security attestations such as SOC 2 and ISO 27001, platform availability expressed as an uptime figure, and support coverage across the regions you operate in. Each is verifiable, and none of them is verified by a vendor saying yes. This guide explains what each attestation actually attests, what it deliberately leaves out, and the specific questions that turn a claim into evidence.

Key Takeaways

  • A certification is a scoped, time-bounded opinion about named controls, not a permanent property of a company. “We are SOC 2 compliant” is not a verifiable statement.
  • SOC 2 Type 1 covers the design of controls at a point in time. Only Type 2 covers whether those controls actually operated effectively over a period.
  • ISO 27001 scope can legitimately cover only part of an organization’s products, services, processes or sites, which means the certificate may exclude the product you are buying.
  • SOC 2 has five trust services criteria and most reports do not cover all of them. Availability is a separate criterion from security, and it is the one that relates to uptime.
  • Ask for the report, the scope statement, the observation period and any noted exceptions. A vendor unwilling to share a scope statement has answered the question.

Why These Three Questions Now Gate TMS Shortlists

The financial case for asking is no longer abstract. IBM’s Cost of a Data Breach Report puts the global average at $4.99 million, a 12% rise year over year and a record, with AI-enabled breaches now accounting for one in four malicious incidents at an average of $6 million each. A TMS holds customer addresses, delivery windows, carrier credentials and often payment-adjacent settlement data, which places it inside the scope of that exposure rather than adjacent to it.

The attack surface grows with every integration, and integration is exactly what an enterprise TMS deployment consists of. Gartner’s survey conducted in October and November 2025 found that more than half of chief supply chain officers, 56% of those surveyed, cite integrating AI with legacy systems as a major challenge. Each connection to an ERP, WMS, OMS or carrier endpoint is both an operational dependency and a credential to be protected.

What makes this worth a dedicated evaluation step rather than a checkbox is that the three claims are routinely conflated. A vendor can hold a genuine SOC 2 Type 2 report covering security only, publish a 99.9% availability figure that is a measured historical average rather than a commitment, and offer support hours that cover two of your four operating regions. All three statements can be true and the combination can still fail your requirements. Separating them is the whole job.

There is also a timing reason to do this early rather than at contract stage. Security review is the step most likely to stall a signed deal, because it is usually the first point at which someone reads the scope documents rather than the summary. A gap discovered then costs a renegotiation and a quarter. The same gap discovered during shortlisting costs one email.

Also Read: Enterprise TMS Security Compliance: A Strategic Guide for Logistics Leaders

What Each Attestation Actually Attests

1. Understand the SOC family before comparing reports

The AICPA maintains the Trust Services Criteria underpinning SOC 2, covering five categories: security, availability, processing integrity, confidentiality and privacy. These are outcome-based criteria used to evaluate whether a system and its controls are effective against objectives management has set.

Two distinctions matter more than anything else in a vendor conversation. The first is type. A Type 1 report addresses the description of the system and the design of controls. A Type 2 report adds the operating effectiveness of those controls over a stated period, which is the difference between a vendor having written a policy and a vendor having followed it. The second is criteria coverage. Most SOC 2 reports do not cover all five categories, and a report scoped to security alone says nothing about availability, which is the criterion that bears on uptime.

SOC 3 is a general-use report containing less detail than SOC 2 and intended for public distribution. A vendor publishing a SOC 3 is being helpful, and it is not a substitute for reading the SOC 2 when you are the one signing.

2. Read the ISO 27001 scope statement, not the certificate

This is the single most overlooked item in TMS security diligence. ISO/IEC 27001:2022 specifies requirements for an information security management system, and ISO’s own guidance is explicit that certification scope is a statement describing the activities, products and services applicable at each site, and that an organization may choose to certify only part of its products, services, processes or sites.

The practical consequence is that a genuine ISO 27001 certificate can exclude the platform you are evaluating. A vendor certified for its corporate IT and its primary data center, but not for the newly acquired module you intend to deploy, is accurately describing itself as ISO 27001 certified. The certificate number tells you nothing. The scope statement tells you everything, and it is a short document. Request the statement of applicability alongside it, since that names which controls from the standard the organization applied and which it excluded with justification. Together those two documents answer in five minutes what a security questionnaire takes six weeks to circle.

3. Separate an availability figure from an availability commitment

Uptime is quoted in two forms that look identical on a slide. A measured historical figure describes what happened. A commitment describes what the vendor undertakes to deliver, and it comes with a definition of downtime, a measurement window, exclusions for planned maintenance, and a remedy if missed. Ask which one you are being shown, then ask how downtime is defined, because a platform that counts only total unavailability will report differently from one that counts degraded performance. The distinction has operational weight in logistics specifically. A dispatch engine that responds in forty seconds instead of two is not down by most definitions, and it is unusable during a dispatch window, so ask whether latency thresholds appear anywhere in the availability definition.

4. Map support coverage against your operating map, not against a label

“24/7 global support” is a marketing phrase rather than a specification. The specification is a table. For each region you operate in, establish the hours during which a human responds, the language, the severity definitions, the target response time per severity, and whether the first responder can resolve or only triage. An operation running evening peaks in three time zones needs coverage during those peaks specifically, which is a narrower and more answerable requirement than round-the-clock everything. Framing it that way also tends to produce a better answer, because a vendor who cannot promise universal coverage can often commit to your actual windows, and a requirement they can meet is worth more than one they will agree to and miss.

5. Ask about subprocessors and data residency together

A TMS rarely runs alone. Mapping and geocoding services, notification providers, cloud regions and carrier APIs all touch data, and each is a subprocessor for data protection purposes. Ask for the subprocessor list, then ask which regions data is processed and stored in. For operations spanning the EU, the UK, the Gulf and North America, residency requirements can differ by market and a single global answer usually means the question has not been examined.

6. Establish the renewal cadence and the last report date

Attestations lapse. A SOC 2 Type 2 observation period ending 14 months ago is a statement about a period that has closed, and the interval since is unexamined. Ask for the current report date, the next scheduled examination, and whether any material change has occurred since, such as a migration, an acquisition or a new region.

Also Read: Enterprise TMS Selection Guide for Logistics 2026

Attestation Decoder

AttestationWhat it attestsWhat it does not tell youWhat to request
SOC 2 Type 1Description of the system and design of controls at a point in timeWhether controls operated effectivelyThe Type 2 report, if one exists
SOC 2 Type 2Operating effectiveness of named controls over a stated observation periodAnything about periods outside that window, or criteria not in scopeReport, observation period, criteria covered, noted exceptions
SOC 3Same subject matter as SOC 2, summarized for public distributionThe detail a buyer needs to assess residual riskThe underlying SOC 2
ISO 27001An information security management system meeting the standard, within a defined scopeWhether the product you are buying is inside that scopeThe scope statement and the statement of applicability
ISO 27701Privacy information management extending the ISMSLawfulness of any specific processing you intendScope statement and processing roles
Uptime figureHistorical availability as measured by the vendorHow downtime is defined, or what happens if it is missedDefinition, measurement window, exclusions
Support tier labelNothing verifiable on its ownRegional hours, severity targets, escalation authorityA per-region coverage and response table

The pattern across every row is the same. The named thing is a container, and the contents are defined by a scope document that is short, specific and usually available on request. Procurement processes that collect the container names and never open them are performing diligence rather than doing it.

Worth noting what this table is not. None of these attestations is a guarantee against a breach, and a vendor with a complete set can still be compromised. What they establish is that controls exist, were examined by a third party, and cover a defined scope. That is meaningfully better than a vendor assertion and meaningfully weaker than a promise, and buyers who understand the difference negotiate better contracts than those who treat the certificate as either worthless or conclusive.

Five Questions to Put in the RFP

1. Provide your most recent SOC 2 Type 2 report, including the observation period and any exceptions noted. Exceptions are normal and their absence is more suspicious than their presence. What matters is whether they were remediated and how quickly. A report with zero exceptions across a twelve-month window is either a very narrow scope or a very light examination, and either is worth a follow-up question.

2. Provide your ISO 27001 scope statement and confirm the module we are purchasing is within scope. Ask for this in writing. It is the fastest way to find a gap that would otherwise surface during a security review after signature, and a written confirmation is worth having on file regardless of what the certificate says.

3. Which trust services criteria does your SOC 2 cover? If availability is not among them, the uptime figure has no attested basis and should be treated as a vendor-reported metric.

4. Give the per-region support coverage table with severity definitions and response targets. Compare it against your own peak hours by region rather than against a competitor’s tier names.

5. List subprocessors and the regions where data is processed and stored. Then confirm this is contractually committed rather than described, and how you will be notified of changes.

Also Read: Dispatch Platform Onboarding Checklist: 10 Questions for 2026

Building the Vendor Comparison Yourself

There is no reliable published table of which TMS vendors hold which attestations, and any table that exists is out of date on the day it publishes, because certifications lapse, renew and change scope on independent cycles. Treat the comparison as something you build during evaluation rather than something you look up.

The practical method is a grid with vendors as rows and seven columns: SOC 2 type, criteria covered, observation period end date, ISO 27001 scope confirmed for the purchased module, uptime figure with its definition, per-region support coverage, and subprocessor list provided. Populate it only from documents rather than from answers given verbally or in a slide. Blank cells are findings, and in practice the pattern of what a vendor supplies quickly is more informative than the contents. A vendor with mature assurance sends a document pack within a day because the pack already exists. A vendor assembling it in response to your question is telling you something about how often the question gets asked.

One caution on interpretation. The absence of a certification is not automatically disqualifying for a smaller or newer vendor, and its presence is not sufficient for a large one. A SOC 2 Type 2 covering security only, at a vendor with no regional support presence, is weaker assurance for a multi-region enterprise than a narrower certification set at a vendor whose scope statement explicitly includes your deployment.

Four Mistakes in Security and Support Diligence

Accepting the certification name without the scope document. The name is the container. Every meaningful distinction lives in the scope statement, and it is the shortest document in the pack.

Treating an uptime percentage as a commitment. A measured historical figure and an undertaking are different claims. Establish which one is on the table before it reaches a contract discussion.

Reading “24/7 global support” as a specification. It is a label. The specification is regional hours, severity definitions, response targets and whether the first responder can act.

Running diligence once, at selection. Attestations expire and scopes change. Set a renewal check at the same cadence as the vendor’s examination cycle rather than at contract renewal, which is usually much later. A calendar reminder tied to the observation period end date costs nothing and catches the case where a vendor quietly narrows scope at renewal.

Also Read: Enterprise TMS: What It Must Deliver in 2026 and Beyond

Why and How Locus Meets Enterprise Assurance Requirements

Locus, the world’s first Decision-Intelligent, Agentic TMS, publishes its security and compliance posture rather than describing it. Locus holds SOC 2 Type II and has obtained a SOC 3 report for public assurance covering security, availability and confidentiality. It is certified to ISO 27001:2022 for its information security management system and to ISO 27701:2019 for privacy information management, and it is compliant with GDPR and with HIPAA for operations handling protected health information.

On data security architecture, AES 256-bit encryption protects data at rest and TLS 1.2 with HTTPS protects data in transit, with high-availability deployments and geographically redundant backups. Locus operates at 99.99% uptime. Full details, including current certification status, are maintained on the Locus Trust page, which is the right place to verify rather than taking any of the above on the strength of a blog post.

On support and operating footprint, the honest answer is a factual one rather than a tier name. Locus serves 360+ enterprise customers across 30+ countries and has delivered 1.5B+ orders, which is the scale at which regional operating presence exists as a matter of necessity rather than as a commitment on a slide. Buyers with specific regional peak-hour requirements should ask for the coverage table described above and evaluate it against their own operating map, and that request is the correct one to make of any vendor including this one.

Locus models 250+ real-world constraints simultaneously across 1,000+ pre-integrated carriers, and six governance mechanisms covering explainability, traceability, evaluation, autonomy levels, execution sandbox and human-in-the-loop mean automated decisions can be traced to the state and logic that produced them. Auditability of AI-generated decisions is becoming its own diligence category, and traceability is what answers it. Buyers evaluating any agentic platform should ask the same question of it that they ask of the security posture: not whether decisions are explainable in principle, but which specific record is produced, retained for how long, and who can retrieve it during an audit.

Locus has been recognized by Gartner for seven consecutive years across multiple research categories, appears in the 2026 Gartner Hype Cycle for AI-powered logistics, features ShipFlex as a Representative Vendor in the 2026 Gartner MCPMS Market Guide, holds Leader designation in the QKS SPARK Matrix for Transportation Management Systems, and ranks #1 on G2 for Route Planning software.

In October 2025, Ingka Investments, the investment arm of Ingka Group, the world’s largest IKEA retailer, acquired Locus. Locus continues to operate independently.

To request current attestation documents and a regional support coverage table, schedule a demo.

Also Read: SaaS TMS: What Enterprises Need to Know in 2026

Frequently Asked Questions (FAQs)

Which TMS vendors offer SOC 2, enterprise SLAs and 24/7 global support?

No reliable published list exists, because attestations lapse, renew and change scope on independent cycles, so any table is dated on publication. Build the comparison during evaluation from documents rather than claims, capturing SOC 2 type and criteria, observation period, ISO 27001 scope, uptime definition, per-region support coverage and subprocessors. Locus publishes its own position on its trust page.

What is the difference between SOC 2 Type 1 and Type 2?

Type 1 covers the description of the system and the design of controls at a point in time. Type 2 additionally covers whether those controls operated effectively across a stated observation period. For a buyer, Type 2 is the meaningful report, because Type 1 confirms a control was designed rather than that it worked.

Does ISO 27001 certification cover the whole vendor?

Not necessarily. ISO guidance is explicit that an organization may certify only part of its products, services, processes or sites, and the certification scope is a statement describing what is included. A vendor can hold a valid certificate that excludes the specific module you are buying, which is why the scope statement matters more than the certificate.

Is a 99.99% uptime figure the same as an SLA?

Not automatically. An availability figure can be a measured historical average or a commitment with a definition of downtime, a measurement window, exclusions and a remedy. Ask which is being presented, and ask how downtime is defined, since platforms differ on whether degraded performance counts.

What should “24/7 global support” mean in a contract?

It should resolve into a table rather than a phrase: for each region, the hours a human responds, the languages available, severity definitions, target response time per severity, and whether the first responder can resolve or only triage. Compare that against your own peak hours by region.

Which SOC 2 criteria relate to uptime?

Availability, which is one of the five trust services criteria alongside security, processing integrity, confidentiality and privacy. Many SOC 2 reports are scoped to security only, in which case the report provides no attested basis for availability claims.

MEET THE AUTHOR
Avatar photo
Ishan Bhattacharya
Lead - Content

Ishan, a knowledge navigator at heart, has more than a decade crafting content strategies for B2B tech, with a strong focus on logistics SaaS. He blends AI with human creativity to turn complex ideas into compelling narratives.

Related Tags:

Previous Post Next Post
best retail delivery software?

Retail & CPG

Best Last-Mile Delivery Software for Enterprise Retail Chains in 2026

Avatar photo

Team Locus

Sep 7, 2026

Explore the best retail delivery software platforms in 2026. Compare features, integrations, and tools to optimize last-mile delivery operations.

Read more

General

Route Optimization for Enterprise 3PLs: Why Multi-Client Routing is a Cost Allocation Problem

Avatar photo

Anas T

Sep 7, 2026

3PLs must co-route clients for density but bill them separately. The same shared route can bill a client $150 or $317 depending on allocation method. Here is the arithmetic.

Read more

Enterprise SLAs, SOC 2 and 24/7 Support: How to Verify TMS Vendor Claims

  • Share iconShare
    • facebook iconFacebook
    • Twitter iconTwitter
    • Linkedin iconLinkedIn
    • Email iconEmail
  • Print iconPrint
  • Download iconDownload
  • Schedule a Demo
glossary sidebar image

Is your team spending more time on fixing logistics plan than running the operation?

  • Agentic transportation management from order intake to freight settlement
  • Route optimization built on 250+ real-world constraints
  • AI-driven dispatch with automatic execution handling
20% Cost Reduction
66% Faster Planning Cycles
Schedule a demo

Insights Worth Your Time

General

Locus 2026 US Consumer Survey: Generative AI isn’t Just Changing How Consumers Shop, it’s Breaking the Demand Patterns US Retail Was Built On

Avatar photo

Ishan Bhattacharya

May 29, 2026

General

Embedded vs Bolted-On AI: The Architecture Question European Logistics Buyers Are Asking

Avatar photo

Aseem Sinha

May 21, 2026

General

Hybrid Fleet Management: How Owned, 3PL, Gig, ICE, and EV Capacity Actually Operate at Most Enterprises

Avatar photo

Aseem Sinha

May 7, 2026

General

US Returns Hit $850 Billion in 2025: Why US Retailers Are Restructuring Reverse Logistics in 2026

Avatar photo

Ishan Bhattacharya

May 7, 2026

SUBSCRIBE TO OUR NEWSLETTER

Stay up to date with the latest marketing, sales, and service tips and news

Locus Logo
Subscribe to our newsletter
Platform
  • Transportation Management System
  • Last Mile Delivery Solution
  • Fulfillment Automation
  • Dispatch Planning
  • Delivery Orchestration
  • Track and Trace
  • Analytics and Insights
Industries
  • Retail
  • FMCG/CPG
  • 3PL & CEP
  • Big & Bulky
  • E-commerce
  • E-grocery
  • Industrial Services
  • Manufacturing
  • Home Services
Resources
  • Use Cases
  • Whitepapers
  • Case Studies
  • E-books
  • Blogs
  • Reports
  • Events & Webinars
  • Videos
  • API Reference Docs
  • Glossary
Company
  • About Us
  • Customers
  • Analyst Recognition
  • Careers
  • News & Press
  • Trust & Security
  • Contact Us
  • Hey AI, Learn About Us
  • LLM Text
ISO certificates image
youtube linkedin twitter-x instagram

© 2026 Mara Labs Inc. All rights reserved. Privacy and Terms

locus-logo

Cut last mile delivery costs by 20% with AI-Powered route optimization

1.5B+Deliveries optimized

99.5%SLA Adherences

30+countries

Trusted by 360+ enterprises worldwide

Get a Complimentary Tailored Route Simulation

locus-logo

Reduce dispatch planning time by 75% with Locus DispatchIQ

1.5B+Deliveries optimized

320M+Savings in logistics cost

30+countries served

Trusted by 360+ enterprises worldwide

Get a Complimentary Tailored Route Simulation

locus-logo

Locus offers Enterprise TMS for high-volume, complex operations

1.5B+Deliveries optimized

320M+Savings in logistics cost

30+countries served

Trusted by 360+ enterprises worldwide

Get a Complimentary Network Impact Assessment

locus-logo

Trusted by 360+ enterprises to slash costs and scale operations

1.5B+Deliveries optimized

320M+Savings in logistics cost

30+countries served

Trusted by 360+ enterprises worldwide

Get a Complimentary Enterprise Logistics Assessment