SOC 2 readiness

SOC 2 ready in six weeks, enforced on every deploy.

Vanta or Drata tells you what is broken. We fix the AWS behind it, put the controls in code so they cannot drift, and export the evidence continuously. Your auditor gets a clean environment and a current trail.

Customers backed by
Y CombinatorSequoiaTiger Global
A week of evidence, once the controls are in code All controls passing
  1. Sage AI

    Access review due. 41 IAM identities listed with last use and approver. Two unused roles flagged for removal.

    Reviewed and signed by the platform lead, Mon 11:20
  2. Sage AI

    Weekly restore test: production database restored to an isolated account from last night's backup. 14 minutes.

    Evidence exported to the compliance platform
  3. ClearRisk

    CVE published for a library in two images. Reachable in one service. Patch pull request opened.

    Merged after review, Wed 16:30
  4. Sage AI

    Deploy blocked: pull request changes a security group without an approver. Returned with the policy that failed.

    Approved and merged with a recorded reviewer
  5. Summary

    Controls passing: 100%. Evidence current for 38 of 38 mapped controls. Nothing waiting on a person.

    Posted to #compliance

Why six weeks

The work is in the infrastructure, not the spreadsheet.

Readiness stalls when controls are documented but not enforced, and when evidence has to be collected by hand. We remove both problems at the source.

Controls as code

IAM, encryption, logging, backups and change management live in Terraform and pipeline policy, with recorded approvals. A control written in code cannot quietly drift back.

Evidence that exports itself

Access reviews, backup tests, key rotation and deploy approvals are produced by the systems that run them and exported continuously. Nobody assembles screenshots in the audit week.

Engineers who have done it before

The same team has taken fintech and crypto companies through readiness while keeping their releases moving. They know which findings matter and which are paperwork.

Week by week

Read-only on day one. Auditor-ready by week six.

  1. Week 1

    Gap review and scorecard

    Read-only access to your AWS and your compliance platform. Every control mapped to what exists today, with a scorecard of what we fix first and what is already fine.

  2. Weeks 2 to 3

    Controls in code

    Sage and ClearRisk put the controls in place: least-privilege IAM, encryption at rest and in transit, centralized logging, backup and restore tests, vulnerability management, and pipeline gates with approvals.

  3. Weeks 4 to 5

    Evidence and operations

    Evidence automation wired to your platform, policies written to match how you actually work, access reviews run, and a disaster recovery run that is tested rather than described.

  4. Week 6

    Readiness review and handoff

    A final pass against the control list with your auditor's requests in mind, then handoff. From here the evidence keeps exporting and the gates keep running.

What ends up in place

Controls you can point an auditor at.

Each one lives in Terraform or pipeline policy in your repositories, so it is enforced by the system rather than by a reminder.

  • Least-privilege IAM with SSO, MFA and a recorded quarterly access review
  • Encryption at rest and in transit on every data store and every load balancer
  • Centralized, immutable logging with retention that matches your policy
  • Backups on a schedule, restore tested regularly, results exported as evidence
  • Vulnerability management: CVEs checked against what runs, patches as pull requests
  • Change management: every infrastructure change is a pull request with a named approver
  • Pipeline gates that block a deploy when a policy fails, with the reason attached
  • Monitoring and incident response with a written process and a tested pager
  • A disaster recovery plan that has been run, not only written
  • Policies and vendor reviews kept in your compliance platform, current

Works with your platform and auditor

We feed the evidence. We do not replace the system of record.

Vanta, Drata, Secureframe or your auditor's own portal stays where it is. We fix what it flags, wire the evidence so it arrives on its own, and answer the auditor's requests from the export rather than from memory.

If you have not chosen a platform yet, we will tell you what each one automates well for an AWS estate and set it up alongside the controls.

Beyond SOC 2

The same controls carry the other frameworks.

ISO 27001, PCI DSS, HIPAA, SLSA Level 3 and GDPR share most of their technical controls with SOC 2. Once the AWS is in code, adding a framework is mostly mapping, not rebuilding.

SOC 2 Type IIControls enforced on every deploy
ISO 27001Information security management
PCI DSSCard data environments
HIPAAHealth data safeguards
SLSA Level 3Signed, verifiable builds
GDPREU data protection

Pricing

Fixed before we start.

SOC 2 readiness is part of the Growth tier of the managed plan, where the same engineers keep running your AWS after the audit. If you only need readiness, it runs as a scoped fixed-price project instead.

No hourly billing and no change orders for routine work. The price is quoted after the week 1 review, once we know how far your environment is from the control list.

See how pricing works

Questions

About SOC 2 readiness.

Is this SOC 2 Type I or Type II?

Readiness in six weeks means the controls are in place, operating and producing evidence, which is what a Type I examines. A Type II report follows the observation window your auditor sets, and the same controls and evidence carry you through it.

Do you replace Vanta or Drata?

No. Your compliance platform stays the system of record. We fix the infrastructure it flags, put the controls in code and feed it evidence, so the dashboard turns green and stays green.

Do you perform the audit?

No. A licensed auditor issues the report. We prepare the environment, map the evidence to their control list and answer their requests during the examination.

We are on GCP or Azure. Does this still work?

Yes. Sage is multi-cloud and the controls translate. Most engagements are on AWS, which is where the deepest automation is, and the six-week timeline assumes an AWS estate.

What does it cost?

SOC 2 readiness is included in the Growth tier of the managed plan, or it runs as a scoped fixed-price project if you only need readiness. Either way the price is fixed before we start and there is no hourly billing.

Will this slow our deployments?

No. The gates run inside the pipeline and approvals are recorded where the pull request already lives. Nobody waits in a queue, and a blocked deploy comes back with the exact policy that failed.

See how far you are from ready.

Book a demo with an engineer. Share your compliance platform's findings on the call and leave with the week 1 review scoped.