SOC 2 · CC7 + CC8

Half your SOC 2 evidence generates itself.

SOC 2 auditors test two things on your codebase: vulnerabilities are tracked and patched (CC7), and changes go through reviewed PRs (CC8). RepoWarden produces audit-ready evidence for both, every month.

Sign in with SSO →

Trust services criteria touched

The Common Criteria (CC) used in every SOC 2 Type II report includes vulnerability management and change management as separate sections. Both expect documented, repeatable processes with retained evidence:

  • CC7.1 Detection of new vulnerabilities. Monthly LLM-deep scans plus continuous Dependabot/CVE ingest.
  • CC7.2 Monitoring of system components. Per-commit scan history with severity classification.
  • CC8.1 Authorisation of changes. Every fix lands as a reviewed PR — RepoWarden never auto-merges.

What the auditor will ask for

Common SOC 2 evidence requests RepoWarden answers:

  • "Show me a sample list of vulnerabilities identified in the audit period." → scan history table.
  • "For high/critical findings, demonstrate remediation timeliness." → ticket lifecycle, in-review → merged.
  • "Show that changes go through review before deploy." → every PR has at least one reviewer; main is protected.
  • "Provide evidence the SDLC includes security review." → CE+ readiness scan running on every active repo.

RepoWarden's own SOC 2 posture

RepoWarden is not yet SOC 2 Type II attested as a vendor — we run on attested infrastructure (Cloudflare, Anthropic, Stripe, GitHub) and document our equivalent controls on /security. Customers pursuing SOC 2 should expect us to complete vendor security questionnaires and provide a DPA on request — no friction.

Get started

Make your audit boring

The best SOC 2 audits are the ones where every evidence request is met with a screenshot, not a Slack scramble. RepoWarden takes the codebase-evidence half off your plate.

Sign in with SSO →