Scrutineer.ai

Scrutineer · By framework

SOC 2 compliance that gets you audit-ready, with evidence

SOC 2 compliance is mostly a paperwork problem disguised as a security problem: you already run access reviews, change management and monitoring, but proving it to an auditor means chasing screenshots, tickets and logs for weeks. Scrutineer maps your existing controls to the five Trust Services Criteria, then collects the evidence behind each one automatically.

As systems change, Scrutineer keeps the mapping current and flags gaps the moment a control drifts, so nothing surprises you in the audit. You see a live readiness view per criterion, the exact evidence attached to each control, and a prioritized list of what to fix first. Scrutineer gets you ready, and your accredited auditor issues the attestation.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with SOC 2 compliance

You choose the scope, and the scope decides most of the work

The single largest driver of SOC 2 effort is a decision made before any control is tested. Security, the common criteria, is in every SOC 2. Availability, confidentiality, processing integrity and privacy are optional categories that management selects, and each one you add brings its own criteria, its own evidence and its own testing. Management also writes the system description that defines which products, environments, locations and people are inside the boundary. Auditors test against what you asserted, not against everything you own. Teams that scope late usually scope wide, because nobody wants to argue about a boundary once the audit has started, and then they spend the year collecting evidence for criteria no customer ever asked about. Scope deliberately, write the boundary down, and make the sales team confirm which categories customers are actually requesting before you commit to them.

Evidence has a date, and the date is what fails

Most control failures in a Type 2 are not design failures. The control existed and the team ran it, but the artifact proving one instance was never captured, or was captured for a different quarter. A Type 2 opinion covers a period, so the auditor samples across it and a missing month is a missing month. This is why evidence collection has to be continuous rather than a project. Access reviews, change approvals, vulnerability remediation, backup restoration tests, vendor reviews and security training all have to leave a dated artifact each time they happen, attached to the control they prove. Scrutineer pulls that evidence from the systems where the work actually happens and timestamps it against the control, so the population you hand the auditor matches the period under review rather than the week you started collecting.

Readiness is our job. The opinion is a licensed CPA firm decision

Only a licensed CPA firm can perform a SOC 2 examination and issue the report, and the opinion in that report is theirs alone. No platform, ours included, can shorten that or influence it. What tooling legitimately changes is everything on your side of the line: whether the control set maps cleanly to the criteria you selected, whether evidence exists for every period sampled, whether gaps were found in month two rather than in fieldwork, and whether the auditor spends their hours testing rather than chasing files. That is also why you should be suspicious of any vendor language implying certification. SOC 2 is an attestation engagement and produces a report with an opinion, not a certificate, and there is no body that certifies anyone against it.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps your existing controls to the Trust Services Criteria you actually selected, so you stop collecting evidence for categories nobody asked for
  • Collects evidence from cloud, identity, ticketing and HR systems and timestamps each artifact against the control it proves
  • Shows live readiness per criterion, with the specific evidence behind every green state rather than a percentage
  • Flags drifted controls and stale evidence during the period, when a gap is still fixable, instead of in fieldwork
  • Keeps the system description boundary explicit, because scope is the decision that drives most of the cost
  • Prioritizes gaps by how likely they are to become an exception in the report, not by how easy they are to close
  • Hands the auditor an organized, dated population per control, which is the part that shortens fieldwork
  • Reuses the same control library for ISO 27001, HIPAA, PCI DSS and vendor risk, so the second framework costs a fraction of the first
SOC 2 compliance readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

SOC 2 report reference

What a SOC 2 report actually asserts, line by line, against what people assume

Nearly every published SOC 2 table compares Type 1 with Type 2, or lists the five Trust Services Categories. Both are true and neither helps when a report is on your desk. The useful axis is the gap between what a reader assumes the report proves and what it says, because that gap is where vendor reviews and sales cycles go wrong in both directions.

What a SOC 2 report is assumed to prove What it actually asserts Who decided that Where to look in the report
The vendor is secure That controls the vendor itself selected were suitably designed, and for a Type 2 operated effectively over a stated period, against the criteria in scope The vendor selected the criteria and wrote the control set. The CPA firm opined on that set The opinion paragraph, then management assertion, then the control listing in section 4
The scope covers the product I use Only if the system description names it. Anything outside the described boundary was never in the engagement Management wrote the system description and the boundary Section 3, the description of the system: products, environments, locations and in-scope infrastructure
All five Trust Services Categories were examined Security, the common criteria, is always included. Availability, confidentiality, processing integrity and privacy appear only if management selected them Management, at scoping time, usually months before you saw the report The opinion paragraph, which names the categories in scope, and the criteria headings in section 4
There were no problems An unqualified opinion and a clean testing section are different things. Exceptions can be listed in the test results under an unqualified opinion The CPA firm judged severity. You judge whether it matters to you Every row of section 4 that says exceptions noted, plus management response
It reflects the vendor today It reflects a period that already ended. The gap between period end and today is covered by nothing Nobody. A bridge letter covering the gap is a management representation, not audit work The period covered on the cover page, then the date of any bridge letter and who signed it
The vendor subservice providers were tested too Under the carve-out method they were not. The report names them and lists the controls assumed of them, and the auditor tested none of those Management chose carve-out or inclusive. Carve-out is far more common The subservice organization section and the complementary subservice organization controls
The vendor is SOC 2 certified Nobody is. SOC 2 is an attestation engagement that produces a report and an opinion. There is no certificate and no certifying body The AICPA attestation standards the engagement is performed under The report itself. If a vendor sends you a certificate instead of a report, ask for the report

This table describes the standard structure of a SOC 2 report under the AICPA attestation standards and the 2017 Trust Services Criteria. Individual reports vary, and only the report in front of you governs what it says, so read the opinion, the system description and the test results rather than a summary of them. Scrutineer prepares readiness evidence; a licensed, independent CPA firm performs the examination and issues the opinion.

Good questions

Questions about SOC 2 compliance

There is no fixed control checklist. A SOC 2 requires you to define a system boundary, select which Trust Services Categories apply, design controls that meet the criteria in those categories, operate them, and evidence that operation across the period. Security is always in scope. The other four categories are selected by management based on what customers ask for.
No. SOC 2 is an attestation engagement performed by a licensed CPA firm under the AICPA attestation standards, and it produces a report containing an opinion. No certificate is issued and no body certifies organizations against it. If a vendor sends you a one-page certificate instead of a report, ask for the report.
The five categories are security, availability, processing integrity, confidentiality and privacy. Security is the common criteria and appears in every SOC 2. The other four are optional and included only when management selects them, which is why two SOC 2 reports can cover very different ground and look identical on a sales slide.
A Type 1 opines on whether controls were suitably designed at a single point in time. A Type 2 opines on design and on whether the controls operated effectively across a period, commonly three to twelve months. Customers who are doing real diligence ask for a Type 2, because design without operation proves very little.
The readiness work usually runs from a few weeks to a few months depending on how much control evidence already exists. After that, a Type 2 requires an observation period, most often three to twelve months, before fieldwork can begin. The observation period is the part nobody can compress, so scope early and start capturing dated evidence immediately.
Only a licensed, independent CPA firm. Consultants, platforms and internal teams can prepare you, map controls and organize evidence, but the examination and the opinion belong to the CPA firm. That independence requirement is also why no readiness platform can promise an outcome.
Dated artifacts proving each control ran when it was supposed to: access review records, change approvals and tickets, onboarding and offboarding records, vulnerability scan and remediation history, backup and restoration tests, security training completion, incident records and vendor reviews. For a Type 2 they sample across the whole period, not the end of it.
A report covers a stated period and does not expire so much as go stale. Most customers treat a report as current for twelve months from the period end date and ask for a bridge letter to cover the gap between period end and today. A bridge letter is a management representation rather than tested audit work, so it carries less weight than the report.
Often yes, because they answer different buyers. US enterprise procurement usually asks for SOC 2, and international buyers usually ask for the ISO certificate. The controls overlap heavily, so the second framework costs far less than the first if you run them from one control library rather than two parallel programs.
We will not quote a figure, because the range is wide and driven by decisions you control: how many Trust Services Categories are in scope, how large the system boundary is, whether you go Type 1 first, how much evidence already exists, and the audit firm you select. Get quotes from at least two firms after your scope is written, not before.
No. Scrutineer gets you audit-ready by mapping controls, collecting evidence and flagging gaps. The actual SOC 2 attestation is issued by an accredited, independent auditor. We make their job (and yours) faster by handing over organized, current evidence.
It removes the manual evidence hunt. Controls are mapped to the Trust Services Criteria once, evidence is pulled automatically and kept current, and gaps are surfaced early, so you walk into the audit with everything organized rather than scrambling at the end.

Keep reading

Guides that go deeper on SOC 2 compliance

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification