SOC 2
SOC 2 Type II workspace — Trust Services Criteria, controls, policies, evidence, tasks, and roadmap.
Where it lives
Frameworks → SOC 2 (/frameworks/soc2)
Service Organization Control 2 Type II — how you protect customer data against the AICPA Trust Services Criteria.
In-page tabs
Readiness ring, TSC breakdown (Security, Availability, Processing Integrity, Confidentiality, Privacy), and the journey: Readiness Assessment → Gap Analysis → Control Mapping → Evidence Collection → Auditor Review → Report Issued.
Trust Services Criteria. Expand for points of focus used in Type II testing.
Filter by TSC category and status (Complete / Partial / Missing). Open a control for mapped tasks and evidence.
Information security and related policies with mapped control chips. Edit to match documents you actually maintain.
Per-control evidence status and attachments (screenshots, tickets, configs).
Seeded SOC 2 work. Filter Open / In Progress / Done. Admins add custom tasks.
Categories ranked by remaining gap so you know what to fund next.
Export Report in the header downloads a SOC 2-oriented PDF.
Security (CC series) is in scope for every SOC 2. Add Availability, Confidentiality, Processing Integrity, and Privacy based on customer contracts.