Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  International

AICPA · SOC 2

Trust Services Criteria evidence.

Applies to: Any vendor asked for a SOC 2 report.

What the signed record shows

Operation-time evidence for monitoring, logical access, and processing integrity.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: CC6.1/CC7.2/CC7.3/CC4.1/PI1.2

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the criteria require, section by section

AICPA Trust Services Criteria (TSP section 100, 2017 criteria as revised). The common-criteria and processing-integrity criteria this mapper evidences from the per-decision signed record:

CC6.1
Logical and physical access controls (restrict logical access; the system whose access is governed, and the authentication state).
CC7.2
System monitoring (monitor system components to detect anomalies; a per-operation monitoring record reference).
CC7.3
Evaluation of security events (security events are evaluated and a response recorded).
CC4.1
Monitoring of controls (ongoing evaluation; an audit/control-monitoring reference per operation).
PI1.2
Processing integrity (inputs are processed completely and accurately; a per-operation processing-input reference).

Taken from the Regulayer entry for this instrument, which is built against the primary text.