TrustEvidence
SOC 2 readiness · continuous monitoring

Know where you stand before your auditor does.

Read-only connections to your cloud, code and identity systems. Scheduled tests against a versioned SOC 2 control catalog, tamper-evident evidence for every result, and fixes you can verify.

  • Free plan
  • No card required
  • Read-only access

Readiness tooling, not an audit: only an independent CPA firm can issue a SOC 2 report.

Illustrative example data. Each cell is one day of a control's history.

83 automated checks across 5 read-only connectors, mapped to 52 controls and the Trust Services Criteria

  • AWS 39 checks
  • GitHub 24 checks
  • Microsoft Azure & Entra ID 10 checks
  • Okta 5 checks
  • Google Workspace 5 checks
How it works

From connection to verified fix

  1. 1

    Connect, read-only

    Use a read-only role or token for each system. Credentials are encrypted with your organisation's own key.

  2. 2

    Test against controls

    Checks run on a schedule and map to SOC 2 controls. Missing permissions show up as missing evidence, never as a pass.

  3. 3

    Keep the proof

    Every result becomes an evidence record: hashed, chained, sealed and kept as daily history for your Type II period.

  4. 4

    Fix and verify

    Findings come with resource-specific console and CLI steps, and close only when a re-scan confirms the fix.

Product

What a SOC 2 programme runs on

Automated checks cover the technical controls. Everything else an auditor asks for is here too.

Type II observation period

Daily control history, drift alerts, time to fix, complete populations and reproducible samples for the period your auditor examines.

Findings that close the loop

Owners, due dates, a ticket you can paste into Jira or GitHub, and time-boxed risk acceptance that needs a second approver.

Policies and acknowledgements

Versioned policies with separation of duties on approval, annual review dates, and acknowledgements bound to the exact version.

Vendors and sub-processors

Criticality, assurance-report validity, review cadence and expiry alerts, with a sub-processor list you can publish.

Continuous monitoring

Scheduled scans, alerts by email or Slack, and a "My work" list for everyone who owns a control, finding or vendor.

Auditor access

A read-only auditor role, readiness reports, and evidence packages with a SHA-256 manifest. Every export is in the audit log.

For auditors

Evidence an auditor can check, not just trust

  • Every evidence record carries a SHA-256 hash, chained to the one before it
  • Records are sealed in Merkle trees (RFC 9162) with per-record inclusion proofs
  • Optional Ed25519 signatures and external anchoring of each seal
  • Organisations are isolated in the database itself, with row-level security
  • Each organisation's data is encrypted under its own key (AES-256-GCM)

What TrustEvidence will not do

  • Certify you. Your CPA firm issues the SOC 2 report.
  • Change your systems. Access is read-only; fixes are yours to apply.
  • Hide gaps. Missing data is reported as missing, not as a pass.
  • Blend it into one score. Coverage, results and findings stay separate.

Start your readiness work today

Free plan: up to 3 members, one account per provider, 90-day evidence retention. No card required.