Control evidence, collected every night.
A scheduled job reads the platform’s own state for ten Trust Services Criteria controls, records a result for each and stores the day’s evidence file. It is evidence collection for our controls, not a certification.
AICPA Trust Services Criteria
Ten controls, one result each.
Each record is marked pass, warn, fail or skip, with the underlying figures kept beside the result.
What this is not. ClairAudit does not state a SOC 2 attestation on this site. For our current assurance position and questionnaires, write to [email protected].
- CC6.1
Logical access provisioning
Users provisioned and deprovisioned in the period.
- CC6.2
Strong authentication
WebAuthn enrolment rate: pass at 90% or above, warn at 50% or above.
- CC7.1
Monitoring
Active continuous-monitoring rules.
- CC8.1
Change management
Deployment events in the last 24 hours.
- CC9.1
Vendor and integration inventory
Connectors configured on the platform.
- A1.1
Availability
Health check result and latency.
- A1.2
Capacity
The twenty largest tables by size.
- C1.1
Confidentiality
Presence of the encryption key configuration.
- PI1.1
Processing integrity
Audit-trail entry volume.
- P1.1
Privacy requests
Data-subject request queue: warn above 100 open requests.
One file per day, kept for review.
The collector runs daily at 02:30 UTC and writes a newline-delimited JSON file to EU object storage, with pass and fail counts in its metadata. Administrators can read the results in the platform.
| Control | Observation | Result |
|---|---|---|
| CC6.2 | WebAuthn enrolment 94% | Pass |
| A1.1 | Health check 200 · 41 ms | Pass |
| P1.1 | 112 open requests | Warn |
Bring an engagement. We will walk the file with you.
A demo covers your audit methodology, the standards you report under, and how agents, citations and review gates would fit your team. Pricing is discussed on the call.