SOC 2 (AICPA Trust Services Criteria)
Controls are explicitly mapped to the criteria — change management to CC8, logging and monitoring to CC7, access control to CC6 — but no SOC 2 attestation of any type exists. Independent attestation is a tracked roadmap item, offered as a contractual milestone for a pilot.
Controls mapped to this standard
Each control page lists the specific requirements it helps satisfy.
Applications · 1
Identity and access control · 4
Cloud infrastructure · 2
Monitoring · 3
Business operations · 2
Policies behind those controls
- Information security policyGovernance
- Compliance postureGovernance
- Access control policyData security and privacy
- Change management policyApplication security
- Phishing and social engineering policySecurity operations
- Logging and monitoring policySecurity operations
- Business continuity and wind-down policySecurity operations
Need the detail behind this page?
Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.