Pentesting for SOC 2
SOC 2 is an AICPA attestation for service organizations. It applies to companies that run cloud, hosting, SaaS, or IT services and need to prove they manage customer data securely. Reports evaluate controls against the Trust Services Criteria, and a current independent pentest is a common part of the evidence. There are no statutory penalties, but a failed or missing report can cost you customers and contracts.
The controls we cover
Requirement summaryUsers are identified and authenticated before they reach protected information assets, and access is restricted to the data and functions their role requires.
AISafe’s web and code audits test whether those access controls actually hold: broken authentication, privilege escalation, and excessive authorization are exactly what the agents probe for.
Requirement summaryLogical access security measures, network segmentation, and firewalls protect the system boundary from attacks originating outside it.
AISafe replays the external attacker’s perspective: blackbox testing and unauthenticated discovery surface exactly the exposure this control is meant to prevent.
Requirement summaryControls prevent, detect, and act on the introduction of unauthorized or malicious software, including unauthorized installation and tampering.
AISafe code audits and dependency checks look for unauthorized or suspicious software paths, malicious libraries, and configuration points that would allow improper code to run.
Requirement summaryDetection and monitoring procedures identify configuration changes that introduce new vulnerabilities, unknown or unauthorized components, and anomalies that indicate security events, with timely remediation.
AISafe’s recurrent scans, change validation, and anomaly analysis help demonstrate that newly discovered vulnerabilities and unauthorized components are detected, prioritized, and fixed.
Requirement summaryChanges to infrastructure, data, software, and procedures are authorized, designed, configured, documented, tested, approved, and implemented to meet the entity’s objectives.
AISafe tests changes before they reach production and after deployment, so findings tie back to specific changes, supporting the requirement to track and protect changes through the lifecycle.
Requirement summaryRisks to the achievement of the entity’s objectives are identified across the organization and analyzed as a basis for deciding how they should be managed, including their likelihood and impact.
AISafe’s reproducible findings, prioritized by severity and exploitability, give the entity a measured basis for estimating the significance of the technical risks it has identified.
Requirement summaryThe entity selects, develops, and performs ongoing or separate evaluations, including continuous monitoring, external assessments, vulnerability scans, and penetration testing, to ascertain whether controls are present and functioning.
AISafe provides the independent technical testing and reproducible findings that feed ongoing and separate evaluations of the vulnerability and monitoring controls.
Quick facts
| Applicability | Service organizations, typically cloud, hosting, SaaS, and IT companies that must show customers their data is protected. |
| Requirement | No legal mandate; it becomes binding through customer and partner contracts. |
| Cost | Scoped by control set and report type; a compact scope keeps a smaller company’s attestation affordable, and automation lowers the evidence cost. |
| Cadence | Commonly yearly; Type II covers an observation period, with additional tests after significant changes. |
AISafe Labs delivers on-demand, audit-ready evidence for SOC 2: scoped reports, reproducible findings, and remediation validation , in hours, where other vendors take weeks to deliver the same. The SOC 2 practitioner decides whether this evidence is sufficient and issues the attestation.
