1Password service has completed SOC 2 type 1 and 2 certification as well. It is more about internal company processes and how they are followed than encryption.
"Hey your data is safe just because we have SOC 2 certification" -- that's not want you want to hear.
"Hey your data is safe just because we have SOC 2 certification" -- that's not want you want to hear.
About vault being encrypted locally: https://hackernoon.com/psa-lastpass-does-not-encrypt-everyth...