COMPLIANCE · SOC 2

SOC 2 Readiness

SOC 2 Type I and Type II readiness assessment — gap analysis and remediation roadmap

📊 Readiness Score Dashboard

0% readiness
Overall SOC 2 Readiness
0 / 64
Controls Implemented
Implemented + Verified
0
Evidence Items
Uploaded & linked
0
Gaps Identified
Critical / Medium / Low
Days to Readiness
Set target date below
⚡ Auto-Collect Evidence
Connect your platforms to automatically collect SOC 2 evidence — no manual screenshots needed.
Connectors: 0 / 6 complete
SOC 2 criteria evidenced: 0 / 64
0 / 64 criteria have evidence
🗄️
Supabase
Database Security
Criteria: CC6.1, CC6.3, CC6.4, CC7.1, CC6.6
Last pulled: Never
🌐
Netlify
Hosting & Deployment
Criteria: CC8.1, CC6.2, CC6.7, CC6.8
Last pulled: Never
🔥
Cloudflare
WAF & Network
Criteria: CC6.6, CC6.7, CC7.1
Last pulled: Never
🐙
GitHub
Code Repository
Criteria: CC8.1, CC6.3, CC7.1, CC6.5
Last pulled: Never
🔵
Google Workspace
Identity
Criteria: CC6.1, CC6.2, CC6.4, CC6.5
Last pulled: Never
Requires service account
🤖
Anthropic API
AI Security
Criteria: CC6.8, CC6.7, CC2.3, CC7.2, C1.1
Last pulled: Never
No credentials needed
Configure Connector

📋 Trust Service Criteria Tracker

CC Common Criteria (Security)
0 / 33 complete
CC1 — CONTROL ENVIRONMENT
CC1.1COSO principles for information security demonstrated0
CC1.2Board of directors or equivalent oversees security0
CC1.3Management establishes organisational structure and reporting lines0
CC1.4Commitment to attract, develop, and retain competent individuals0
CC1.5Accountability for control responsibilities enforced0
CC2 — COMMUNICATION & INFORMATION
CC2.1Information generated and used by entity to support internal controls0
CC2.2Internal communication of security objectives and responsibilities0
CC2.3External communication with relevant parties about security0
CC3 — RISK ASSESSMENT
CC3.1Risk assessment objectives are specified0
CC3.2Risks to achieving objectives are identified and analysed0
CC3.3Fraud risk considered in risk assessment0
CC3.4Changes in business, technology, and environment assessed for risk0
CC4 — MONITORING ACTIVITIES
CC4.1Ongoing and separate evaluations to ascertain controls are present and functioning0
CC4.2Control deficiencies communicated and corrective action taken0
CC5 — CONTROL ACTIVITIES
CC5.1Mitigating controls selected and developed over identified risks0
CC5.2Technology general controls selected and developed to support control objectives0
CC5.3Controls deployed through policies and procedures0
CC6 — LOGICAL & PHYSICAL ACCESS CONTROLS
CC6.1Logical access security measures to protect against unauthorised access0
CC6.2Prior to issuing system credentials, registered users authenticated0
CC6.3Role-based access control limits user access to authorised objects0
CC6.4Access credentials reviewed and removed when no longer needed0
CC6.5Logical access to protected information assets discontinued on termination0
CC6.6Logical access security measures implemented to protect against external threats0
CC6.7Transmission and movement of information restricted to authorised users0
CC6.8Controls to prevent or detect and act upon malicious software0
CC7 — SYSTEM OPERATIONS
CC7.1System vulnerabilities detected and monitored on an ongoing basis0
CC7.2Anomalies and incidents detected and responded to0
CC7.3Incidents evaluated and classified; response executed0
CC7.4Incident recovery procedures to restore system to its required state0
CC7.5Identified vendor and business partner components managed and tracked0
CC8 — CHANGE MANAGEMENT
CC8.1Changes to infrastructure, data, software, and procedures authorised and managed0
CC9 — RISK MITIGATION
CC9.1Risk mitigation activities including transfer of risk0
CC9.2Business disruption risk assessed and managed through vendor and business partner management0
A Availability
0 / 3 complete
A1.1Availability commitments and system requirements met0
A1.2Environmental protections, software, data backup processes and recovery infrastructure0
A1.3Recovery plan procedures exist to recover system components0
C Confidentiality
0 / 2 complete
C1.1Confidential information identified and maintained0
C1.2Confidential information disposed of when no longer needed0
PI Processing Integrity
0 / 5 complete
PI1.1Processing completeness — inputs completely processed0
PI1.2Processing accuracy — data accurately processed0
PI1.3Processing validity — only valid processing is performed0
PI1.4Processing completeness — outputs completely and accurately produced0
PI1.5Processing accuracy — outputs distributed to correct recipients0
P Privacy (AICPA GAPP)
0 / 8 complete
P1Notice and communication of objectives related to personal information0
P2Choice and consent — individuals provided options regarding personal information0
P3Collection of personal information limited to that identified in objectives0
P4Use, retention, and disposal of personal information consistent with objectives0
P5Access — individuals able to review and update their personal information0
P6Disclosure and notification of personal information to third parties0
P7Quality — personal information accurate, complete, and relevant0
P8Monitoring and enforcement of privacy program0

🤖 AI Gap Assessment

AI analyses all 64 criteria statuses and produces a prioritised gap report with remediation recommendations.

🔐 Evidence Locker

📎
Drop evidence files here or click to upload
PDF, DOCX, XLSX, PNG, JPG — max 10MB per file
FilenameTypeCriterionUploadedSHA-256Status

📅 Readiness Timeline

Gap assessment complete
Policies written and approved
Controls implemented
Evidence collected
Pre-audit readiness review
Type I audit window
Type II observation period start
Type II audit complete