Your SOC 2 gaps are mostly documents nobody wroteFind out which, before the auditor does

Scores all 55 Trust Services controls against live cloud evidence, tells you which failures are configuration and which are a missing policy, and lets you close a gap by explaining it, with the verdict re-scored in front of you.

Try it

Interactive demo with a completed Type II assessment, no signup, no cloud account

How It Works

Collect, map, score, close.

01

Collect

Short-lived read-only credentials sweep 41 evidence categories across identity, encryption, network, logging, backup and threat detection, with anything unreadable reported rather than assumed clean.

02

Map

Every category is mapped to the Trust Services Criteria it supports, so a security group rule lines up against CC6.6 and an audit trail against CC7.2.

03

Score

Each of the 55 controls is scored individually with a confidence, observations citing exact field values, remediation steps and the specific artifacts still outstanding.

04

Close

Write how a control actually works or attach the policy, and that control is re-evaluated immediately, with a before and after verdict and an explanation of what was accepted.

What You Can Do

Everything the readiness assessment does.

All 55 Trust Services controls

The full AICPA TSC 2017 (revised 2022) matrix across 13 categories, Common Criteria CC1 to CC9 plus Availability, Confidentiality, Processing Integrity and Privacy, each with its criterion, point of focus, evidence requirements and testing procedure.

See it in the demo

Type I and Type II

Type I scores design as of a date. Type II scores operating effectiveness across a window, and every evidence request then demands samples spanning the full period rather than a convenient snapshot.

See it in the demo

41 evidence collectors

Identity, credentials and MFA; keys and secrets; storage, databases and volumes; certificates, load balancers and CDN; security groups, network ACLs and flow logs; audit trails, log groups, alarms and metric filters; threat detection, configuration recording, vulnerability assessment and backup.

See it in the demo

It reports what it could not read

A permission denial or a disabled service is recorded as pending with its likely cause, never counted as a passing control. An assessment that quietly skips what it cannot see is worse than no assessment.

See it in the demo

Observations that cite the evidence

Not "MFA is inconsistent" but the identity, the field and the value, so the finding can be verified, disputed or fixed without another round of questions.

See it in the demo

Honest scoring you can reproduce

Partial counts as half and Not Applicable leaves the denominator. The formula is published on screen, so scoping a control out raises the score legitimately instead of hiding a failure.

See it in the demo

Interrogate the raw evidence

Ask which identities lack MFA or whether every bucket blocks public access, and get an answer citing the exact field values and the category file it came from, with clickable citations into the JSON.

See it in the demo

Close gaps by explaining them

Most SOC 2 failures are undocumented controls rather than absent ones. Write how the control operates or attach the policy and it is re-scored immediately, with a before and after verdict and updated remediation.

See it in the demo

It will not accept hand-waving

A vague sentence changes nothing, and a written description cannot close a control that failed for lack of evidence. The assessment says so and holds the verdict, which is what makes a cleared gap worth anything.

See it in the demo

Business Outcomes

What it changes.

Sooner

Readiness is known months before fieldwork, when a missing recovery test can still be performed inside the audit window rather than explained away after it.

Sorted

Configuration failures and documentation failures are separated, so the engineering backlog and the policy backlog go to different people on day one.

Closable

A gap you can explain is a gap you can close in the tool, with the reasoning recorded, instead of a spreadsheet cell that says "in progress" for two quarters.

See your readiness before the auditor does.

Connect a read-only role and the first assessment scores all 55 controls in a few minutes.