This is a sample preview. The real auditor portal is token-gated and loads live programme data.

All numbers, evidence titles, findings, and policy entries on this page are synthetic and refer to no real organisation.

Acme Logistics (sample)

Auditor packet — SOC 2 Type II — surveillance Q3 2026 · Sample Audit Co.

Scope

Frameworks
SOC2, ISO27001
Period
2026-01-012026-06-30
Generated
sample preview

Control coverage

FrameworkImplementedTotalCoverage
soc218720193%
iso27001899396%

Operating effectiveness (Type II)

Window
181 days
Start
2026-01-01
End
2026-06-30
Evidence collected
1,842 items / 184 controls

Evidence (6 of 1,842 shown)

TitleControlFrameworkCollectedStatus
AWS IAM access review — Q1 2026CC6.1soc22026-03-31collected
GitHub branch-protection snapshotCC8.1soc22026-04-12collected
Okta MFA enforcement exportCC6.6soc22026-04-15collected
Patch cadence — production fleetA.8.8iso270012026-05-02collected
Backup integrity test — restore drillA.8.13iso270012026-05-18collected
Quarterly access certification — financeCC6.2soc22026-06-12collected

Internal audit findings (2)

ControlFindingSeverityStatus
CC7.2One vendor security review overdue (review cycle 30 days, last reviewed 47 days ago).minorremediated
A.8.16Two SIEM alert rules without documented runbook references.lowin_progress

Approved policies (4)

PolicyFrameworkLast updated
Information Security Policyiso270012026-05-14
Access Control Policyiso270012026-04-22
Incident Response Proceduresoc22026-05-30
Business Continuity Planiso270012026-03-11

A working audit surface — not just a data room

Evidence requests (PBC)

Your auditor requests specific evidence; you’re emailed, respond and attach the exact items, and they accept, reject or ask for follow-up — the whole loop in one place.

Control walkthrough

A per-control view of status, the evidence mapped to it and the policies that satisfy it — export any control’s full evidence population to CSV for sampling.

Continuity proof

A per-control calendar of daily evidence collection across the period — visual proof a control operated throughout, with coverage % and longest-gap detection.

Tamper-evident evidence

Every evidence item is sealed with a SHA-256 hash at collection and re-verified on view — provenance (which connector, when) is shown for each.

Named-auditor access

Give each auditor their own magic link — individually revocable, with their actions attributed to them. No shared passwords.

SOC 2 Section III

Author the system description, subservice orgs and CUECs — with an AI first draft — shown read-only to the auditor and in the packet PDF.

This is what your auditor will see.

The real surface is token-gated, scope-bounded by frameworks and date range, and pulled directly from your live programme — no copy-paste, no manual extract.