SOC 2 auditors test two things on your codebase: vulnerabilities are tracked and patched (CC7), and changes go through reviewed PRs (CC8). RepoWarden produces audit-ready evidence for both, every month.
The Common Criteria (CC) used in every SOC 2 Type II report includes vulnerability management and change management as separate sections. Both expect documented, repeatable processes with retained evidence:
Common SOC 2 evidence requests RepoWarden answers:
RepoWarden is not yet SOC 2 Type II attested as a vendor — we run on attested infrastructure (Cloudflare, Anthropic, Stripe, GitHub) and document our equivalent controls on /security. Customers pursuing SOC 2 should expect us to complete vendor security questionnaires and provide a DPA on request — no friction.
The best SOC 2 audits are the ones where every evidence request is met with a screenshot, not a Slack scramble. RepoWarden takes the codebase-evidence half off your plate.