Industry
SECURITYFRAMEWORKSOC 2

Pentesting for SOC 2

SOC 2 is an AICPA attestation for service organizations. It applies to companies that run cloud, hosting, SaaS, or IT services and need to prove they manage customer data securely. Reports evaluate controls against the Trust Services Criteria, and a current independent pentest is a common part of the evidence. There are no statutory penalties, but a failed or missing report can cost you customers and contracts.

The controls we cover

Requirement summary

Users are identified and authenticated before they reach protected information assets, and access is restricted to the data and functions their role requires.

AISafe’s web and code audits test whether those access controls actually hold: broken authentication, privilege escalation, and excessive authorization are exactly what the agents probe for.

Requirement summary

Logical access security measures, network segmentation, and firewalls protect the system boundary from attacks originating outside it.

AISafe replays the external attacker’s perspective: blackbox testing and unauthenticated discovery surface exactly the exposure this control is meant to prevent.

Requirement summary

Controls prevent, detect, and act on the introduction of unauthorized or malicious software, including unauthorized installation and tampering.

AISafe code audits and dependency checks look for unauthorized or suspicious software paths, malicious libraries, and configuration points that would allow improper code to run.

Requirement summary

Detection and monitoring procedures identify configuration changes that introduce new vulnerabilities, unknown or unauthorized components, and anomalies that indicate security events, with timely remediation.

AISafe’s recurrent scans, change validation, and anomaly analysis help demonstrate that newly discovered vulnerabilities and unauthorized components are detected, prioritized, and fixed.

Requirement summary

Changes to infrastructure, data, software, and procedures are authorized, designed, configured, documented, tested, approved, and implemented to meet the entity’s objectives.

AISafe tests changes before they reach production and after deployment, so findings tie back to specific changes, supporting the requirement to track and protect changes through the lifecycle.

Requirement summary

Risks to the achievement of the entity’s objectives are identified across the organization and analyzed as a basis for deciding how they should be managed, including their likelihood and impact.

AISafe’s reproducible findings, prioritized by severity and exploitability, give the entity a measured basis for estimating the significance of the technical risks it has identified.

Requirement summary

The entity selects, develops, and performs ongoing or separate evaluations, including continuous monitoring, external assessments, vulnerability scans, and penetration testing, to ascertain whether controls are present and functioning.

AISafe provides the independent technical testing and reproducible findings that feed ongoing and separate evaluations of the vulnerability and monitoring controls.

Quick facts

ApplicabilityService organizations, typically cloud, hosting, SaaS, and IT companies that must show customers their data is protected.
RequirementNo legal mandate; it becomes binding through customer and partner contracts.
CostScoped by control set and report type; a compact scope keeps a smaller company’s attestation affordable, and automation lowers the evidence cost.
CadenceCommonly yearly; Type II covers an observation period, with additional tests after significant changes.

AISafe Labs delivers on-demand, audit-ready evidence for SOC 2: scoped reports, reproducible findings, and remediation validation , in hours, where other vendors take weeks to deliver the same. The SOC 2 practitioner decides whether this evidence is sufficient and issues the attestation.

Related frameworks

Get your Audit Evidence right now

Run a security assessment of your system, or contact us if your compliance programme requires additional support.