AGICOMPLY
Client LoginBook Founder Triage
SOC 2 READINESS FOR AI SAAS

Prepare the evidence before the CPA examination or enterprise review.

Organize one AI service's supplied control evidence into a bounded, reviewer-traceable readiness package before a SOC 2 examination or customer assurance decision.

ENGAGEMENTATO Readiness Baseline
FIXED SCOPE$3,500
BOUNDARYOne AI service · One review context
Check Fit and Receive Written Scope
SOC 2 READINESS ASSESSMENT

Prepare one AI SaaS service for a defined examination or customer-assurance boundary.

The assessment connects system scope, control design, operating-period evidence, exceptions, and remediation priorities without crossing into the independent CPA firm's examination or report.

Read the SOC 2 readiness assessment guide
ACTIVE SALES DEPENDENCY

When a buyer asks for SOC 2, the immediate problem is usually evidence readiness.

The examination may still be ahead, but procurement already needs support for security representations, system boundaries, control ownership, operating history, and unresolved exceptions. The Baseline establishes what the current record can support before those questions are answered too broadly.

Run the 90-Second Reviewability Check
READINESS EVIDENCE

Four evidence areas that determine whether the handoff survives review.

The package remains tied to the exact AI service, intended examination scope, authorized criteria source, supplied evidence set, and assessment date.

EVIDENCE AREA

System and examination boundary

Service commitments, infrastructure, software, people, procedures, data, system interfaces, subservice organizations, and customer responsibilities identified for the intended examination scope.

EVIDENCE AREA

Control design evidence

Current policies, access design, change procedures, incident processes, risk records, vendor oversight, data handling, and control ownership tied to the defined AI service.

EVIDENCE AREA

Operating-period evidence

Dated access reviews, approved changes, security results, recovery tests, incident exercises, exceptions, remediation records, and other recurring artifacts needed to examine operation over time.

EVIDENCE AREA

AI-specific customer evidence

Model and dependency records, intended-use boundaries, testing and limitation evidence, human-oversight procedures, change history, and accountable approval records relevant to customer review.

BASELINE OUTPUTS

The same five deliverables, prepared for a SOC 2 and customer-assurance handoff.

No new subscription or competing offer. The review context changes; the evidence method and fixed commercial scope remain controlled.

01

Evidence Inventory

A structured register of supplied artifacts, their source, format, date, owner, and content hash.

02

Mapping Summary

Human-verified links between supplied evidence and the review requirements within the agreed scope.

03

Gap Register

A bounded record of missing, unclear, stale, or insufficiently supported evidence items.

04

Ordered Remediation Plan

Sequenced evidence actions organized around review dependencies and submission priorities.

05

Chain-of-Custody Statement

A record of evidence handling, SHA-256 content hashing, and review activity during the engagement.

CPA HANDOFF INDEX

Give the independent service auditor a bounded starting position.

  • Which AI service, environment, locations, dependencies, and subservice organizations are inside the intended examination boundary?
  • Which supplied artifacts support each applicable Trust Services Criteria question, and what limitation applies to that relationship?
  • Which controls are designed but do not yet have sufficient operating-period evidence?
  • Which evidence populations, samples, exceptions, owners, and review dates must be prepared for the independent service auditor?
  • Which enterprise security questionnaire answers can be supported by current evidence, and which must remain conditional?
  • Can the evidence position be reconstructed after an artifact, control, or system component changes?
TYPE I AND TYPE II

Design evidence and operating evidence are not interchangeable.

A point-in-time design position can identify whether controls are described and supported at a specified date. A Type II examination also requires evidence of operation throughout the examination period. AGICOMPLY separates those states so missing recurring evidence does not become an unsupported effectiveness claim.

BUYER QUESTIONS

What AGICOMPLY establishes and what remains with the CPA firm.

ANSWER

Does AGICOMPLY issue a SOC 2 report?

No. AGICOMPLY provides a readiness evidence package. An independent, qualified CPA firm performs the SOC 2 examination and issues the report.

ANSWER

Is this SOC 2 certification or a compliance determination?

No. SOC 2 is an attestation examination, not a software certification. The Baseline records the supplied evidence position, accepted mappings, gaps, limitations, and remediation priorities before examination.

ANSWER

Can this support a Type II examination?

Yes, as pre-examination readiness work. A Type II examination requires evidence that controls operated throughout the period selected with the CPA firm. AGICOMPLY can identify missing operating-period evidence but does not test or attest to control effectiveness.

ANSWER

Which Trust Services categories are included?

The intended scope begins with Security. Availability, Confidentiality, Processing Integrity, or Privacy are added only when the customer commitments and intended CPA examination require them. The authorized criteria source and exact scope are confirmed before mapping.

ANSWER

Can the same work help with enterprise security questionnaires?

Yes. Current evidence can be organized to support customer assurance responses while preserving unsupported, conditional, or not-yet-established answers as explicit gaps.

ANSWER

Do we need to purchase another compliance platform?

No. Source systems can remain where they are. The $3,500 Baseline is a fixed-scope evidence assessment with no annual AGICOMPLY license requirement.

ADJACENT PROCUREMENT PATH

Use the same evidence position for customer assurance questions.

A security questionnaire records representations. A reviewer-traceable package shows which current artifacts support those representations, who accepted the relationship, and what remains unresolved.

Compare evidence packages and security questionnaires
SOC 2 READINESS BASELINE

Establish what the current evidence can support before examination.

$3,500 fixed scope. One AI service and one intended SOC 2 or customer assurance review context. No annual license required.