Define the scope
Agree on the systems, responsibilities, criteria, and period included in the examination.
Bring access decisions, governed actions, and a traceable history into the wider control evidence your SOC 2 review requires.
SOC 2 examinations address controls relevant to selected Trust Services Criteria. The system description, scope, assessment period, and auditor’s work determine the report. Product records can contribute evidence; they cannot provide an audit opinion.
Give reviewers the actor, decision, and supporting record for work captured within the workspace.
Explore trust and securityAgree on the systems, responsibilities, criteria, and period included in the examination.
Review account access, governed decisions, and available audit history within that scope.
Supply relevant records alongside policy documents, control testing, and independent assurance work.
These are architecture-alignment topics, not a SOC 2 control crosswalk. The receipt catalog does not currently map Trust Services Criteria.
Product evidenceWorkspace roles, account security controls, and recorded administrative changes.
Review limitsOrganization-wide access reviews and offboarding evidence extend beyond this workspace.
Product evidencePolicy decisions and required approval records for actions on the enforcement path.
Review limitsOther systems and changes outside that path need their own control evidence.
Product evidenceAppend-only audit history and chained receipts for captured activity.
Review limitsIntegrity checks do not demonstrate the effectiveness of every control over an assessment period.
Architecture alignment describes relevant product mechanisms. It does not establish a framework mapping, audit opinion, or legal compliance.
Use the relevant records within the evidence program defined with your auditor.
Selected Trust Services Criteria and examination scope
Control ownership, testing, and assessment-period evidence
System description, service commitments, and external dependencies
We do not currently claim a SOC 2 attestation. Contact our team for the current assessment status and available security-review evidence.
No. A conformance packet presents scoped product records and selected AI-framework references. A SOC 2 report is the result of an independent examination.
No. This page describes relevant architecture and evidence topics. It does not claim an implemented Trust Services Criteria crosswalk or complete examination coverage.
Framework requirements and their interpretation should be checked against the authoritative source.
Walk through the scope, available evidence, and remaining requirements with our team.