Honest answer: SOC 2 is not built. ISO 27001 is the only framework mapped in the engine today, and its infrastructure evidence is live. Because the policy engine is framework-agnostic, SOC 2 is a control mapping rather than a rewrite — and it ships when the companies we serve, and their auditors, tell us it is the blocker. If that is you, this page is how you tell us.
The deterministic policy engine that evaluates 133 ISO 27001 policies across AWS and Kubernetes is the one that will evaluate SOC 2 trust criteria. No rewrite — a mapping.
Access control, encryption, logging, change management — most of the infrastructure evidence SOC 2 asks for is already collected under its ISO 27001 mapping today.
We committed publicly: no feature ships from reflex. Enough design partners asking for SOC 2 un-gates the build — your request is literally the input.
32 kinds of AWS resource, 92 ISO 27001 checks. Every unsafe change becomes a dated record naming the exact resource.
13 adapters, 41 ISO-mapped policies — RBAC, NetworkPolicy, ResourceQuota, and namespaces evidenced beside your AWS findings.