Type II observation period
Daily control history, drift alerts, time to fix, complete populations and reproducible samples for the period your auditor examines.
TrustEvidence
Read-only connections to your cloud, code and identity systems. Scheduled tests against a versioned SOC 2 control catalog, tamper-evident evidence for every result, and fixes you can verify.
Readiness tooling, not an audit: only an independent CPA firm can issue a SOC 2 report.
83 automated checks across 5 read-only connectors, mapped to 52 controls and the Trust Services Criteria
Use a read-only role or token for each system. Credentials are encrypted with your organisation's own key.
Checks run on a schedule and map to SOC 2 controls. Missing permissions show up as missing evidence, never as a pass.
Every result becomes an evidence record: hashed, chained, sealed and kept as daily history for your Type II period.
Findings come with resource-specific console and CLI steps, and close only when a re-scan confirms the fix.
Automated checks cover the technical controls. Everything else an auditor asks for is here too.
Daily control history, drift alerts, time to fix, complete populations and reproducible samples for the period your auditor examines.
Owners, due dates, a ticket you can paste into Jira or GitHub, and time-boxed risk acceptance that needs a second approver.
Versioned policies with separation of duties on approval, annual review dates, and acknowledgements bound to the exact version.
Criticality, assurance-report validity, review cadence and expiry alerts, with a sub-processor list you can publish.
Scheduled scans, alerts by email or Slack, and a "My work" list for everyone who owns a control, finding or vendor.
A read-only auditor role, readiness reports, and evidence packages with a SHA-256 manifest. Every export is in the audit log.
Free plan: up to 3 members, one account per provider, 90-day evidence retention. No card required.