SOC 2 in plain terms
SOC 2 is an attestation report on how a company protects customer data. An independent auditor, a licensed CPA firm, examines your controls against the Trust Services Criteria published by the AICPA and writes a report you can share with customers.
Security is the one criterion every SOC 2 report covers. Availability, processing integrity, confidentiality, and privacy are optional, and are added when they matter to your customers. Startups usually meet SOC 2 when a larger customer's security review asks for it.
Type I and Type II
A Type I report looks at whether your controls are designed properly at a point in time. A Type II report looks at whether they operated effectively over a period, commonly three to twelve months.
Type II is the reason monitoring matters. Saying you watch for security events is not enough. You have to show that you did, across the whole period.
What an auditor asks about security operations
Among the security criteria, the system operations requirements cover how you detect, evaluate, and respond to security events. In practice an auditor asks questions like these.
- How do you detect security events in your systems?
- How do you decide which events are incidents?
- How do you respond, and who approves it?
- Can you show records of that happening during the audit period?
What Jutsu contributes
Jutsu does the monitoring, investigation, and response work, and keeps the record of it.
- Monitoring: connected Google Cloud, Google Workspace, GitHub, Windows host, Cloudflare, Vercel, and Railway sources are watched around the clock.
- Triage and investigation: each alert gets a category, severity, risk score, and verdict, and uncertain ones are escalated to a person.
- Response records: every AgentSOAR execution is recorded with its status, and approval-based response is included from the Startup plan.
- Reports: incident reports and SOC activity reports, daily and weekly on the Startup plan.
- Posture checks: read-only compliance posture checks for connected Google Cloud projects and Google Workspace domains, and osquery on Windows hosts, on plans that include compliance.
- Evidence exports: SOC 2 evidence exports from the Startup plan, with continuous compliance evidence and compliance dashboards on Growth.
What stays with you and your auditor
SOC 2 covers more than security operations. Jutsu's part is monitoring, response, and the evidence that comes from them. The rest stays with your team, your auditor, and whatever compliance process you run.
Jutsu does not issue SOC 2 reports and does not guarantee an audit outcome.
- Written policies and procedures.
- Risk assessment and vendor reviews.
- People controls such as onboarding, offboarding, and training.
- Choosing an auditor, scoping the report, and the audit itself.
How this differs from a compliance-only tool
A compliance-only platform is organized around the audit: policies, checklists, and collecting proof. Jutsu runs the security work itself and uses the records of that work as evidence. The two do different jobs: one tracks the program, the other does the monitoring the program promises.
