It works from the controls you describe rather than from your systems, so what comes back is the structured readiness view a consultant would draft first — the matrix, the gaps and the evidence list — with the collection still ahead of you.
A SOC 2 readiness toolkit. You describe the controls you have and it assesses them against the five Trust Services Criteria — security, availability, processing integrity, confidentiality and privacy — then produces the gap list, the control matrix, the evidence checklist and a remediation order.
- Your controls assessed against all five Trust Services Criteria, or against a single principle you name
- The gaps between what you have and what SOC 2 asks for, listed rather than described
- A control matrix generated from your controls and the evidence you hold against each
- An overall audit-readiness score across the principles
- An evidence checklist per principle, so you know what an auditor will ask to see
- A remediation plan that puts the findings in order against a timeline
Python, installed from PyPI or through Smithery. There is a free tier, with Pro and Enterprise plans the vendor bills monthly.
Build from source — clone the repository and build it, then point your client at the binary
