SOC 2 readiness
Last updated 2026-09-25. CheckTrail does not have a SOC 2 report. This is the checklist to get
one, and a recommendation on tooling.
1. Plan
- Scope: Trust Services Criteria for Security (required, the Common Criteria), plus
Availability and Confidentiality, which broker-dealer reviewers commonly ask about.
Processing Integrity and Privacy: not in the first report.
- Type I first (controls designed and in place on a date), then Type II (controls operating
over 3–6 months, later 12).
- Order: close the "Not done" items below → pick a compliance platform and auditor → policies
approved → Type I → observation window → Type II.
- Nothing should be bought until the cost is confirmed and approved. A realistic trigger is the
first firm that makes SOC 2 a condition of signing.
2. Checklist mapped to the Trust Services Criteria
Status: Done, Partial, Not done.
CC1 — Control environment
| Control |
Status |
Evidence / next step |
| Security responsibility assigned |
Done |
Founder named in every policy |
| Code of conduct, confidentiality agreement (for future staff) |
Not done |
Template from the compliance platform |
| Security awareness training (annual) |
Not done |
Founder completes and records yearly |
| Background checks for future hires |
Not done |
Policy only |
CC2 — Communication and information
| Control |
Status |
Evidence / next step |
| System description and data flow |
Done |
../data-flow.md, data-flow-diagram.md |
| Security information for customers |
Partial |
This trust package; public security page (Prompt 11) |
| Way for customers/researchers to report issues |
Not done |
security@ mailbox |
| Customer contracts with security commitments (incl. 72-hour notice) |
Not done |
Draft with counsel |
CC3 — Risk assessment
| Control |
Status |
Evidence / next step |
| Annual risk assessment with risk register |
Not done |
Use platform template |
| Fraud risk considered |
Not done |
Include insider/founder risk |
| Vendor risk assessment |
Partial |
subprocessors.md; DPAs and SOC 2 reports not collected |
CC4 — Monitoring activities
| Control |
Status |
Evidence / next step |
| Periodic control review |
Not done |
Quarterly access review; platform continuous monitoring |
| Pen test yearly |
Not done |
Book before first live firm |
| Audit-chain verification scheduled |
Partial |
npm run audit:verify being added; schedule it (e.g. daily) and alert on failure |
CC5 — Control activities
| Control |
Status |
Evidence / next step |
| Written policies approved and reviewed yearly |
Partial |
Trust docs exist; formal approval and review dates needed |
| Segregation of duties |
Partial |
One person: compensate with logging, locked records, external review |
CC6 — Logical and physical access
| Control |
Status |
Evidence / next step |
| MFA on all production systems |
Partial |
Policy says required; screenshot evidence per system not collected |
| App: required 2FA, lockout, session timeouts |
Done |
auth.ts, login.ts |
| App: RBAC, branch scoping, tenant isolation tests |
Done |
rbac.ts, tenancy.db.test.ts |
| SSO for customers |
Partial |
Being built |
| Least-privilege machine identities |
Done (code) |
checktrail_app grants; infra/terraform/iam.tf — apply and evidence |
| Quarterly access reviews |
Not done |
First at go-live |
| Onboarding/offboarding checklist |
Not done |
For future staff |
| Encryption in transit and at rest |
Done (design) |
SSE-KMS, TLS, field encryption; evidence after Terraform apply |
| Key management (rotation, restricted use) |
Done (code) |
KMS rotation on; key deletion alarm Not done |
| Endpoint security (disk encryption, updates) |
Not done |
Verify founder laptop; record |
| Physical security |
N/A |
Inherited from AWS, Neon, Netlify (carve-out; get their SOC 2 reports) |
CC7 — System operations
| Control |
Status |
Evidence / next step |
| Vulnerability scanning (dependencies) |
Not done |
CI with npm audit, Dependabot |
| Logging and monitoring of infrastructure |
Partial |
App audit log, S3 access logs; CloudTrail trail and alerts Not done |
| Error monitoring |
Partial |
Sentry being added |
| Incident response plan |
Done |
incident-response-plan.md |
| Incident response tested |
Not done |
Tabletop exercise, record results |
CC8 — Change management
| Control |
Status |
Evidence / next step |
| Version control for all code and infrastructure |
Done |
Git; Terraform |
| Required automated tests before production deploy |
Not done |
CI + branch protection on main |
| Change approval |
Partial |
One person: use pull requests with CI as the gate and a written change log |
| Database changes via reviewed migrations only |
Done |
Prisma migrations; records triggers |
CC9 — Risk mitigation
| Control |
Status |
Evidence / next step |
| Vendor management (DPAs, SOC 2 reports yearly) |
Not done |
See subprocessors.md table |
| Cyber insurance |
Not done |
Get quotes |
| Business continuity plan |
Done |
business-continuity.md |
A1 — Availability
| Control |
Status |
Evidence / next step |
| Backups (PITR, versioned locked storage) |
Done |
Neon PITR window to confirm; S3 Object Lock |
| Restore tested |
Not done |
Run procedure A, record in test log |
| Capacity / uptime monitoring |
Not done |
External uptime check (confirm cost; many are free) |
| RTO/RPO defined |
Partial |
Targets set, not validated |
C1 — Confidentiality
| Control |
Status |
Evidence / next step |
| Confidential data identified and classified |
Partial |
../data-flow.md; formal classification policy Not done |
| Data minimisation (last 4 only, metadata stripping) |
Done |
uploads.ts, schema |
| Retention and disposal |
Partial |
Retention enforced; disposal after retention Not done |
3. Vanta or Drata for a one-person company
Pricing must be confirmed with each vendor. Neither publishes full list prices. Third-party
comparisons published in 2026 put entry-level SOC 2 packages at roughly $7,500–$10,000 a year for
Drata and $10,000 a year or more for Vanta, with startup discounts sometimes available and
renewal increases reported for both. The audit itself is extra (typically several thousand
dollars for a Type I from a small CPA firm; get quotes). Neither is in PAID_ASSETS.md; do not
start a trial without approving the cost.
| Factor |
Vanta |
Drata |
| Entry price (third-party estimates, confirm) |
Higher |
Lower (roughly $2,500/yr less at entry level) |
| Auditor network |
Large; auditors familiar with the platform are easy to find |
Large; also a partner network, slightly smaller by most accounts |
| AWS integration |
Yes |
Yes |
| GitHub integration |
Yes |
Yes |
| Google Workspace integration |
Yes |
Yes |
| Netlify integration |
Confirm with vendor — may need manual evidence |
Confirm with vendor — may need manual evidence |
| Neon integration |
Likely manual evidence (confirm) |
Likely manual evidence (confirm) |
| Policy templates, training, background-check workflows |
Yes |
Yes |
| Public trust page for customers |
Yes (Trust Center) |
Yes (Trust Center) |
Recommendation: Drata, on price, for a one-person company where both products cover the same
core integrations (AWS, GitHub, Google Workspace) and Netlify/Neon evidence will likely be uploaded by
hand either way. Choose Vanta instead if its quote comes within a few hundred dollars, or if a
preferred auditor works only with Vanta. Get written quotes from both, ask each to confirm Netlify
and Neon support, and ask for startup pricing. Buy only when a customer requires SOC 2 or the
pipeline justifies it.
Sources for the price ranges (third-party, not vendor price lists):
soc2auditors.org — Vanta vs Drata (2026),
secureleap.tech — Vanta vs Drata 2026,
datavirtualizer.com — pricing comparison.
4. What the founder must do by hand
- Apply Terraform in a sandbox, then production; collect screenshots (bucket lock settings, key
rotation, IAM policy).
- Apply the AWS AI services opt-out policy; keep evidence.
- Turn on MFA on every production console; screenshot each.
- Enable CloudTrail and alarms.
- Set up CI, Dependabot, branch protection.
- Run and record the first restore test and the first tabletop exercise.
- Collect subprocessor DPAs and SOC 2 reports.
- Engage counsel (recordkeeping questions, customer contract, Reg S-P terms).
- Book a pen test.
- Get quotes: Vanta, Drata, two or three SOC 2 auditors, cyber insurance.