← Security

SOC 2 readiness

Last updated 2026-09-25. CheckTrail does not have a SOC 2 report. This is the checklist to get one, and a recommendation on tooling.

1. Plan

  1. Scope: Trust Services Criteria for Security (required, the Common Criteria), plus Availability and Confidentiality, which broker-dealer reviewers commonly ask about. Processing Integrity and Privacy: not in the first report.
  2. Type I first (controls designed and in place on a date), then Type II (controls operating over 3–6 months, later 12).
  3. Order: close the "Not done" items below → pick a compliance platform and auditor → policies approved → Type I → observation window → Type II.
  4. Nothing should be bought until the cost is confirmed and approved. A realistic trigger is the first firm that makes SOC 2 a condition of signing.

2. Checklist mapped to the Trust Services Criteria

Status: Done, Partial, Not done.

CC1 — Control environment

Control Status Evidence / next step
Security responsibility assigned Done Founder named in every policy
Code of conduct, confidentiality agreement (for future staff) Not done Template from the compliance platform
Security awareness training (annual) Not done Founder completes and records yearly
Background checks for future hires Not done Policy only

CC2 — Communication and information

Control Status Evidence / next step
System description and data flow Done ../data-flow.md, data-flow-diagram.md
Security information for customers Partial This trust package; public security page (Prompt 11)
Way for customers/researchers to report issues Not done security@ mailbox
Customer contracts with security commitments (incl. 72-hour notice) Not done Draft with counsel

CC3 — Risk assessment

Control Status Evidence / next step
Annual risk assessment with risk register Not done Use platform template
Fraud risk considered Not done Include insider/founder risk
Vendor risk assessment Partial subprocessors.md; DPAs and SOC 2 reports not collected

CC4 — Monitoring activities

Control Status Evidence / next step
Periodic control review Not done Quarterly access review; platform continuous monitoring
Pen test yearly Not done Book before first live firm
Audit-chain verification scheduled Partial npm run audit:verify being added; schedule it (e.g. daily) and alert on failure

CC5 — Control activities

Control Status Evidence / next step
Written policies approved and reviewed yearly Partial Trust docs exist; formal approval and review dates needed
Segregation of duties Partial One person: compensate with logging, locked records, external review

CC6 — Logical and physical access

Control Status Evidence / next step
MFA on all production systems Partial Policy says required; screenshot evidence per system not collected
App: required 2FA, lockout, session timeouts Done auth.ts, login.ts
App: RBAC, branch scoping, tenant isolation tests Done rbac.ts, tenancy.db.test.ts
SSO for customers Partial Being built
Least-privilege machine identities Done (code) checktrail_app grants; infra/terraform/iam.tf — apply and evidence
Quarterly access reviews Not done First at go-live
Onboarding/offboarding checklist Not done For future staff
Encryption in transit and at rest Done (design) SSE-KMS, TLS, field encryption; evidence after Terraform apply
Key management (rotation, restricted use) Done (code) KMS rotation on; key deletion alarm Not done
Endpoint security (disk encryption, updates) Not done Verify founder laptop; record
Physical security N/A Inherited from AWS, Neon, Netlify (carve-out; get their SOC 2 reports)

CC7 — System operations

Control Status Evidence / next step
Vulnerability scanning (dependencies) Not done CI with npm audit, Dependabot
Logging and monitoring of infrastructure Partial App audit log, S3 access logs; CloudTrail trail and alerts Not done
Error monitoring Partial Sentry being added
Incident response plan Done incident-response-plan.md
Incident response tested Not done Tabletop exercise, record results

CC8 — Change management

Control Status Evidence / next step
Version control for all code and infrastructure Done Git; Terraform
Required automated tests before production deploy Not done CI + branch protection on main
Change approval Partial One person: use pull requests with CI as the gate and a written change log
Database changes via reviewed migrations only Done Prisma migrations; records triggers

CC9 — Risk mitigation

Control Status Evidence / next step
Vendor management (DPAs, SOC 2 reports yearly) Not done See subprocessors.md table
Cyber insurance Not done Get quotes
Business continuity plan Done business-continuity.md

A1 — Availability

Control Status Evidence / next step
Backups (PITR, versioned locked storage) Done Neon PITR window to confirm; S3 Object Lock
Restore tested Not done Run procedure A, record in test log
Capacity / uptime monitoring Not done External uptime check (confirm cost; many are free)
RTO/RPO defined Partial Targets set, not validated

C1 — Confidentiality

Control Status Evidence / next step
Confidential data identified and classified Partial ../data-flow.md; formal classification policy Not done
Data minimisation (last 4 only, metadata stripping) Done uploads.ts, schema
Retention and disposal Partial Retention enforced; disposal after retention Not done

3. Vanta or Drata for a one-person company

Pricing must be confirmed with each vendor. Neither publishes full list prices. Third-party comparisons published in 2026 put entry-level SOC 2 packages at roughly $7,500–$10,000 a year for Drata and $10,000 a year or more for Vanta, with startup discounts sometimes available and renewal increases reported for both. The audit itself is extra (typically several thousand dollars for a Type I from a small CPA firm; get quotes). Neither is in PAID_ASSETS.md; do not start a trial without approving the cost.

Factor Vanta Drata
Entry price (third-party estimates, confirm) Higher Lower (roughly $2,500/yr less at entry level)
Auditor network Large; auditors familiar with the platform are easy to find Large; also a partner network, slightly smaller by most accounts
AWS integration Yes Yes
GitHub integration Yes Yes
Google Workspace integration Yes Yes
Netlify integration Confirm with vendor — may need manual evidence Confirm with vendor — may need manual evidence
Neon integration Likely manual evidence (confirm) Likely manual evidence (confirm)
Policy templates, training, background-check workflows Yes Yes
Public trust page for customers Yes (Trust Center) Yes (Trust Center)

Recommendation: Drata, on price, for a one-person company where both products cover the same core integrations (AWS, GitHub, Google Workspace) and Netlify/Neon evidence will likely be uploaded by hand either way. Choose Vanta instead if its quote comes within a few hundred dollars, or if a preferred auditor works only with Vanta. Get written quotes from both, ask each to confirm Netlify and Neon support, and ask for startup pricing. Buy only when a customer requires SOC 2 or the pipeline justifies it.

Sources for the price ranges (third-party, not vendor price lists): soc2auditors.org — Vanta vs Drata (2026), secureleap.tech — Vanta vs Drata 2026, datavirtualizer.com — pricing comparison.

4. What the founder must do by hand

  1. Apply Terraform in a sandbox, then production; collect screenshots (bucket lock settings, key rotation, IAM policy).
  2. Apply the AWS AI services opt-out policy; keep evidence.
  3. Turn on MFA on every production console; screenshot each.
  4. Enable CloudTrail and alarms.
  5. Set up CI, Dependabot, branch protection.
  6. Run and record the first restore test and the first tabletop exercise.
  7. Collect subprocessor DPAs and SOC 2 reports.
  8. Engage counsel (recordkeeping questions, customer contract, Reg S-P terms).
  9. Book a pen test.
  10. Get quotes: Vanta, Drata, two or three SOC 2 auditors, cyber insurance.