Solutions · Compliance evidence
Change evidence, written as the change ships.
If every change arrives as a pull request already checked against policy, and a named person merges it, the SOC2 change-management evidence an auditor samples is written while the work happens. TruStacks exports it for a time window, mapped to the controls it supports, so the evidence binder becomes a query instead of a project your platform team stops shipping to assemble.
What an auditor asks about a change
Each answer already has a home.
- What changed, and why?Your git provider
- The pull request body: a summary, the blast radius, how to roll it back, and the policy rules the change was written against.
- What was it checked against?TruStacks, exportable
- The policy verdict, allow or deny, with the rule id behind every denial. A denied proposal never becomes a pull request.
- Who approved it?Your git provider
- The merge. Agents have no merge path, so a person on your team merges, and your git provider records who reviewed and who merged.
The binder is a query
Pick a window. Export the evidence.
Audit evidence report
Choose a time window and, optionally, the services inside your audit boundary. Recorded change events are mapped onto CC5.1, CC6.1, CC6.8, CC7.1, CC8.1, and CC9.1, and exported as JSON or a PDF with a SHA-256 checksum.
SOC2 specialist
Control-readiness findings mapped to the Common Criteria, each with up to three hints naming where in your declared stack the artifact an auditor will ask for comes from. Included from the Developer tier.
A score you cannot flatter
Every gap analysis carries a bronze, silver, or gold tier computed by code, not a model. A claim we cannot check earns half credit, so attestation alone cannot reach gold.
To be clear about scope. The report presents evidence; your auditor forms the opinion. It covers the changes that go through TruStacks, and it covers change management, not the rest of SOC2. Keep the evidence platform you already use; this gives it better material to collect. And TruStacks does not hold its own SOC2 report yet. The specialist helps with yours, which is a different thing.
See an evidence report built from your own changes.
Hosted Beta signup is open, capped at 100 teams. Create your workspace at app.trustacks.com, and the hosted quickstart walks you to your first governed pull request.