67%
SOC 2 Type II
Trust Services Criteria · 8 of 12 controls ready · 4 need attention
8
Controls ready
4
Need attention
Controls mapped to SOC 2
| Control | SOC 2 requirement | Status | Source | Expert |
|---|---|---|---|---|
AC-2 MFA enforced on all accounts | Passing | Org | JO | |
AC-7 Quarterly access reviews | Failing | Org | None | |
VR-1 Vendor risk assessments | In review | Org | None | |
GV-1 Information security policy | Passing | Org | JO | |
DP-3 Data encrypted at rest and in transit | Passing | Org | JO | |
BC-2 Backups tested and recoverable | Passing | Org | JO | |
AI-1 No indirect prompt-injection paths | Passing | AI | JO | |
AI-2 Agent tool access allowlisted | Passing | AI | JO | |
SC-4 No secrets in source or prompts | Failing | Code | None | |
SC-1 Dependencies free of known CVEs | Passing | Code | None | |
SC-2 Static analysis on every PR | In review | Code | None | |
LM-1 Audit logging on critical systems | Passing | Org | JO |