SOC 2 · Trust Services for AI

SOC 2SHIPPED ON INFRASTRUCTURE YOU ALREADY OWN

Pre-mapped Trust Services controls, continuous evidence, and auditor-ready export packs — so your next Type I or Type II runs on a workflow your team can actually deliver.

SOC 2 IN 60 SECONDS

Trust Services audit

An AICPA examination that proves how you protect customer data across Security, Availability, Confidentiality, Processing Integrity, and Privacy.

AI is now in scope

The 2024 trust services updates pulled AI systems, vendors, and shadow tools directly into the Common Criteria — generic GRC tools were not built for it.

Type I, then Type II

Type I proves your controls exist on a date. Type II proves they ran for 6–12 months — and that observation window has already started.

THE SOC 2 PROBLEM NOBODY WARNED YOU ABOUT

These are the gaps that stall SOC 2 programs — and quietly burn your audit budget before fieldwork even starts.

Problem 1

Auditors are scoping AI into every engagement

AI systems, model vendors, and shadow tools now show up across CC, A, and C criteria — and your old GRC tool has no native AI registry to point at.

Problem 2

Evidence lives in seven different places

Policies in Notion, vendors in a spreadsheet, incidents in Jira, change tickets in GitHub — auditors reject screenshots and demand timestamped, access-controlled trails.

Problem 3

Shadow AI is now an audit finding

Unsanctioned ChatGPT, Claude, and Copilot accounts show up as control gaps under CC6.1, CC6.6, and CC7.1 — firewall logs cannot prove governance.

Problem 4

Type II costs triple without automation

A 12-month observation window with manual collection burns 200+ engineering hours — automation cuts that to roughly 20.

Problem 5

Vendor and sub-processor diligence is uneven

CC9.2 expects current DPAs, AI-specific due diligence, and sub-processor disclosure — most teams cannot produce it in one place on demand.

Problem 6

Incidents and corrective actions go undocumented

CC7.3–CC7.5 require root cause, corrective action, and effectiveness verification on a clock — informal Slack threads will not survive fieldwork.

Problem 7

Enterprise buyers now require SOC 2 plus AI governance

Fortune 1000 RFPs bundle SOC 2 Type II with explicit AI governance attestations — losing one loses the deal.

WHAT YOU GET WITH RAIC

Buyer outcomes first. Every value below maps to a control your auditor already plans to test.

Pre-mapped Trust Services library

Every Common Criterion (CC1–CC9), Availability, Confidentiality, Processing Integrity, and Privacy criterion ships pre-linked to a RAIC module so engineers stop translating audit-speak into tickets.

Continuous evidence collection

Policy attestations, control tests, vendor reviews, and incident records timestamp themselves into a hash-chained audit trail your auditor can verify independently — no more screenshot scavenger hunts before fieldwork.

Shadow AI discovery built in

Browser-extension and Microsoft Graph telemetry surface unsanctioned AI tools the moment an employee logs in, then promote them into your registry with one click for CC6 and CC7 coverage.

Auditor-ready export packs

One-click bundles deliver your Risk Register, control test results, vendor inventory, incident log, policy library, and Trust Services mapping in the format Big Four auditors expect.

Shared-responsibility disclosures done right

RAIC labels every inherited control — physical security, backup infrastructure — so your auditor sees a defensible boundary instead of a coverage gap.

WHAT'S INSIDE THE SOC 2 MODULE

Each module satisfies a named Trust Services Criterion — and produces the artifact your auditor will request.

AI System Registry with owners

Satisfies CC1.3 and CC2.1 with a current inventory of every AI system, its data classification, business owner, and lifecycle state.

Risk Register with 5×5 heatmap

Satisfies CC3.1–CC3.4 with quantified likelihood × impact scoring, residual-risk tracking, and treatment plans linked to controls and owners.

Policy Library with attestation tracking

Satisfies CC1.4 and CC5.3 — 10 pre-drafted AI policies including Acceptable Use, Agent Use, and Vendor AI with versioned distribution and signed attestations.

Control Library with test cadence

Satisfies CC4.1 and CC4.2 by scheduling control tests, capturing pass/fail evidence, and auto-flagging overdue tests before your auditor does.

Vendor and sub-processor register

Satisfies CC9.2 with DPA tracking, AI-specific due diligence, sub-processor disclosure, and uploaded evidence files — purpose-built for SOC 2 vendor sections.

Incident and nonconformity management

Satisfies CC7.3–CC7.5 with a five-stage workflow from detection through root cause, corrective action, and effectiveness verification.

Internal Audit Programme

Satisfies CC4.1 with a full audit lifecycle that doubles as your Type II self-assessment evidence.

Trust Portal with NDA gating

Satisfies CC2.3 and helps you respond to customer security questionnaires 80% faster with a controlled, audit-logged evidence room.

PRICING THAT MATCHES YOUR SOC 2 READINESS STAGE

Pick the tier that matches where your audit sits today. Move up as your scope grows.

Starter — $349/month

For pre-audit teams scoping their first Type I — core registry, policy library, and control tracking for small environments.

Professional — $999/month

For teams in Type I or early Type II with Shadow AI discovery, vendor management, internal audits, and Trust Portal included.

Enterprise — $1,800/month

For Type II and multi-framework programs with the full AI compliance suite, Aslan AI drafting, EU AI Act and ISO 42001 modules, recertification packs, and a dedicated trust portal. Annual-purchase only with multi-year discount.

MSP & Partner pricing

For managed service providers delivering SOC 2 readiness assessments — multi-tenant launcher, fleet dashboard, and free demo sandboxes included.

Starter and Professional save 20% annual and 28% multi-year. Enterprise is annual-purchase only with a multi-year discount.

WHY MOVE NOW

SOC 2 expectations changed in 2024, the Type II clock is already running for fiscal-year 2026, and enterprise buyers will not renegotiate. The window to start without burning audit budget is short.

  • AI sits in every 2026 audit scope — auditors no longer ask whether you use AI, they ask how you govern it.
  • Enterprise RFPs bundle SOC 2 Type II with explicit AI governance attestations — losing one loses the deal.
  • Type II clocks are already running — a clean fiscal-year 2026 report needs controls operating today.
  • EU AI Act and ISO 42001 are stacking up — RAIC delivers SOC 2 plus both from a single control environment.
Trust Services pre-mapped, CC through Privacy
Continuous evidence with a verifiable, hash-chained audit trail
One platform for SOC 2 + ISO 42001 + EU AI Act
NEW · In-platform assessment

SOC 2 Framework Assessment

Run a scored SOC 2 readiness assessment inside RAIC and export the results — plus the underlying evidence — as an audit-ready download. Stop rebuilding the same gap analysis in spreadsheets.

Scored assessment

Question-by-question readiness scoring with maturity bands, owner assignment, and re-assessment cadence.

Mapped to the standard

Every item maps to the AICPA Trust Services Criteria (CC1–CC9, A1, C1, PI1, P1–P8) — so a single answer drives both the score and the evidence trail.

Downloadable evidence

Export a branded DOCX report plus a ZIP of the underlying evidence (RhindonCyber_SOC-2-Assessment_*.docx + .zip) — ready to hand to your auditor.

Framework Assessment + downloadable evidence is available on ISO 42001, NIST AI RMF, EU AI Act, SOC 2, CIS Controls v8.1, and HIPAA.

TAKE THE NEXT STEP

Three doors. One team. Pick the one that fits where your SOC 2 program is today.