Rhindon Cyber logo
    Support & Documentation
    Contact Support

    SOC 2 Type 2 Evidence

    A Professional and Enterprise module for tracking AICPA Trust Services Criteria (TSC) across your SOC 2 Type 2 audit period. Pre-mapped to RAIC's existing AI governance registers — policies, risks, incidents, suppliers, monitoring — so most evidence assembles itself.

    Enabling the module

    1. An OrgAdmin opens Admin → Org Settings and toggles Enable SOC 2 Type 2 Evidence.
    2. The 61-row TSC catalog is seeded automatically on first enable.
    3. A new SOC 2 Type 2 Evidence entry appears in the sidebar under Regulatory Frameworks at /governance/soc2.

    The module is triple-gated: tier (Pro/Ent) + per-org toggle + (optional) platform feature flag. Disabling the toggle hides the module without deleting any data.

    Trust Services Criteria catalog

    The canonical 61-row catalog covers:

    • Common Criteria (CC1–CC9) — 33 rows (control environment, communication, risk, monitoring, control activities, logical/physical access, system operations, change management, risk mitigation).
    • Availability (A1) — 3 rows.
    • Confidentiality (C1) — 2 rows.
    • Processing Integrity (PI1) — 5 rows.
    • Privacy (P1–P8) — 18 rows.

    Each row carries status (not_started, in_progress, met, not_met, na), owner, last-reviewed date, and free-text notes.

    Evidence & backfill

    Per-control evidence uploads use server-side SHA-256 hashing with the canonical 5-minute signed-URL download chokepoint. The one-click Backfill panel auto-links existing RAIC artifacts — policies, risks, incidents, suppliers, monitoring plans, attestations — to the 28 mappable TSCs so OrgAdmins start the audit with most evidence already attached.

    The Evidence Pack panel assembles approved evidence into a branded ZIP for the external auditor, mirroring the Recertification Pack and Trust Portal evidence patterns.

    Exports

    CSV and branded DOCX exports follow the canonical filename convention RhindonCyber_SOC2-ControlRegister_<slug>_<YYYY-MM-DD>. MSP-managed tenants with the White-Label add-on inherit the partner firm's branding automatically through the platform's white-label canonicals (e.g. AcmeCyberCo_SOC2-…).

    Audit trail

    Every action emits an audit code to both the org Activity Log and the Platform Audit Log under the soc2 family, including:

    • SOC2_MODULE_TOGGLED
    • SOC2_CONTROL_STATUS_CHANGED
    • SOC2_EVIDENCE_UPLOADED / _DOWNLOADED / _DELETED
    • SOC2_EVIDENCE_LINKED / _UNLINKED
    • SOC2_BACKFILL_RUN
    • SOC2_EVIDENCE_PACK_BUILT / _DOWNLOADED
    • SOC2_REGISTER_EXPORTED