SOC 2 scanning aid
Map Trust Service Criteria gaps on connected systems — access, encryption, change evidence, and ingest integrity — so teams can collect findings before an auditor does.
What is SOC 2?
SOC 2 (System and Organization Controls 2) is an AICPA attestation. Security (common criteria CC1–CC9) is required. Confidentiality, Availability, Processing Integrity, and Privacy are optional. Secure Raven’s own Type I target is Security plus Confidentiality. Availability is later. Privacy is not selected.
A Type I report is a point-in-time design opinion. A Type II report samples operating effectiveness over a 6–12 month window. Only a CPA firm can issue either report. Secure Raven is not independently audited for Type I or Type II.
Secure Raven is a scanning and evidence aid. It maps findings to TSC labels on systems you connect. It is not a SOC 2 report, does not replace an auditor, and does not mean a customer or Secure Raven itself is SOC 2 attested.
Key Facts
- Governing Body
- AICPA
- Secure Raven target
- Type I — Security + C1
- Secure Raven today
- Controls mapped — not audited
- Type II
- Requires a CPA observation window
- Trust Center
- /trust — claims stay false
What Secure Raven maps for SOC 2
Scanning and evidence on systems you connect — not a certification or attestation.
Mapped TSC findings
Ravens and control runs attach findings to TSC labels such as CC6.1 access and CC6.7 encryption. That is a catalog, not an attestation.
Watch is scheduled inspection
Watch re-runs safe Ravens on a source. It is not 24/7 XDR and does not prove Type II operating effectiveness.
Evidence you can export
Tenant audit export and finding history are timestamped under RLS. They are not a CPA workpaper pack and must not include raw restricted payloads.
Gap analysis on what you connect
HIPAA Hawk, Auth, RLS, Storage, and Secrets Ravens surface technical gaps. They do not score your whole company against all five TSC categories.
Auditor kickoff map
docs/HIPAA_SOC2_READINESS.md and docs/audits/CONTROLS.md list live vs planned controls. Hand those to a CPA. Do not hand this marketing page as a report.
Remediation stays in findings
Critical and high findings block Secure Raven’s own release. Customer remediation is tracked as findings, not as an automated Type II exception log.
Controls we cover
Mapped, monitored, or supported labels — not an attestation that you or Secure Raven passed SOC 2.
Map SOC 2 gaps on systems you connect
Connect a system and run the mapped Ravens. This is a scanning aid — not a Type I or Type II report.