Has anyone gone through an SOC 2 Type II audit and do you have any recommendations for a firm or application/software?