Compliance

SOC 2 scanning aid

Map Trust Service Criteria gaps on connected systems — access, encryption, change evidence, and ingest integrity — so teams can collect findings before an auditor does.

What is SOC 2?

SOC 2 (System and Organization Controls 2) is an AICPA attestation. Security (common criteria CC1–CC9) is required. Confidentiality, Availability, Processing Integrity, and Privacy are optional. Secure Raven’s own Type I target is Security plus Confidentiality. Availability is later. Privacy is not selected.

A Type I report is a point-in-time design opinion. A Type II report samples operating effectiveness over a 6–12 month window. Only a CPA firm can issue either report. Secure Raven is not independently audited for Type I or Type II.

Secure Raven is a scanning and evidence aid. It maps findings to TSC labels on systems you connect. It is not a SOC 2 report, does not replace an auditor, and does not mean a customer or Secure Raven itself is SOC 2 attested.

Key Facts

Governing Body
AICPA
Secure Raven target
Type I — Security + C1
Secure Raven today
Controls mapped — not audited
Type II
Requires a CPA observation window
Trust Center
/trust — claims stay false
Product

What Secure Raven maps for SOC 2

Scanning and evidence on systems you connect — not a certification or attestation.

Mapped TSC findings

Ravens and control runs attach findings to TSC labels such as CC6.1 access and CC6.7 encryption. That is a catalog, not an attestation.

Watch is scheduled inspection

Watch re-runs safe Ravens on a source. It is not 24/7 XDR and does not prove Type II operating effectiveness.

Evidence you can export

Tenant audit export and finding history are timestamped under RLS. They are not a CPA workpaper pack and must not include raw restricted payloads.

Gap analysis on what you connect

HIPAA Hawk, Auth, RLS, Storage, and Secrets Ravens surface technical gaps. They do not score your whole company against all five TSC categories.

Auditor kickoff map

docs/HIPAA_SOC2_READINESS.md and docs/audits/CONTROLS.md list live vs planned controls. Hand those to a CPA. Do not hand this marketing page as a report.

Remediation stays in findings

Critical and high findings block Secure Raven’s own release. Customer remediation is tracked as findings, not as an automated Type II exception log.

Controls

Controls we cover

Mapped, monitored, or supported labels — not an attestation that you or Secure Raven passed SOC 2.

ControlIDStatus
Logical Access
CC6.1
monitored
Encryption in Transit
CC6.6
monitored
Encryption at Rest
CC6.7
monitored
Vulnerability Detection
CC7.1
supported
Incident Response
CC7.3
supported
Change Management
CC8.1
supported
Confidentiality
C1.1
monitored
Availability
A1.1
supported
Vendor Management
CC9.2
supported
CC+C1
Type I target scope
Mapped
Controls in product
Aid
Not a CPA report
Off
Gate E stays closed

Map SOC 2 gaps on systems you connect

Connect a system and run the mapped Ravens. This is a scanning aid — not a Type I or Type II report.