ShipShape and SOC 2
We produce evidence for one control. We are not an auditor and we cannot make you SOC 2 compliant.
The control we speak to
CC7.1
The entity uses detection and monitoring procedures to identify changes to configurations that introduce new vulnerabilities, and susceptibilities to newly discovered vulnerabilities.
What we produce for it
- A dated scan record for each site, with its own reference, listing every check attempted and its result.
- A schedule: monthly re-scans on a stated cadence, which is what turns a one-off test into 'monitoring procedures'.
- Change tracking between scans, so you can show what appeared, what was fixed, and when.
- An explicit list of what was NOT tested on each scan, which is what an auditor asks for second.
What we do NOT do
- We are not a CPA firm and we do not perform any part of a SOC 2 audit.
- SOC 2 covers your whole organisation — access control, change management, HR, vendor management, incident response. Application scanning is one control out of dozens.
- No scanner can make you compliant, and any vendor implying otherwise is selling you something they cannot deliver.
Run a scan
Free, and the report states its own scope.