Skip to content
Compliance frameworks / SOC 2

Make operational evidence easier to examine.

Bring access decisions, governed actions, and a traceable history into the wider control evidence your SOC 2 review requires.

Independent assurance
Architecture alignment

Assurance depends on controls and how they operate.

SOC 2 examinations address controls relevant to selected Trust Services Criteria. The system description, scope, assessment period, and auditor’s work determine the report. Product records can contribute evidence; they cannot provide an audit opinion.

Move from a control question to a traceable event.

Give reviewers the actor, decision, and supporting record for work captured within the workspace.

Explore trust and security
01

Define the scope

Agree on the systems, responsibilities, criteria, and period included in the examination.

02

Collect operating records

Review account access, governed decisions, and available audit history within that scope.

03

Support the assessment

Supply relevant records alongside policy documents, control testing, and independent assurance work.

Connect review topics with available records.

These are architecture-alignment topics, not a SOC 2 control crosswalk. The receipt catalog does not currently map Trust Services Criteria.

Review topicProduct evidenceReview limits

Access and responsibility

Product evidenceWorkspace roles, account security controls, and recorded administrative changes.

Review limitsOrganization-wide access reviews and offboarding evidence extend beyond this workspace.

Governed activity

Product evidencePolicy decisions and required approval records for actions on the enforcement path.

Review limitsOther systems and changes outside that path need their own control evidence.

Record integrity

Product evidenceAppend-only audit history and chained receipts for captured activity.

Review limitsIntegrity checks do not demonstrate the effectiveness of every control over an assessment period.

Architecture alignment describes relevant product mechanisms. It does not establish a framework mapping, audit opinion, or legal compliance.

Keep independent assurance at the center of the review.

Use the relevant records within the evidence program defined with your auditor.

  • 01

    Selected Trust Services Criteria and examination scope

  • 02

    Control ownership, testing, and assessment-period evidence

  • 03

    System description, service commitments, and external dependencies

Questions about SOC 2?

Does Orcinta have a SOC 2 report?

We do not currently claim a SOC 2 attestation. Contact our team for the current assessment status and available security-review evidence.

Does a conformance packet replace a SOC 2 report?

No. A conformance packet presents scoped product records and selected AI-framework references. A SOC 2 report is the result of an independent examination.

Are SOC 2 criteria mapped in the receipt catalog?

No. This page describes relevant architecture and evidence topics. It does not claim an implemented Trust Services Criteria crosswalk or complete examination coverage.

Read the primary references.

Framework requirements and their interpretation should be checked against the authoritative source.

Bring your assurance requirements into the conversation.

Walk through the scope, available evidence, and remaining requirements with our team.

We do not currently use analytics or advertising cookies. Cookie policy · Privacy policy