ATStatus
ATStatus WikiLoading documentation...

SOC 2 Readiness

✓ Audit-Ready Controls

ATStatus provides technical controls aligned with SOC 2 Trust Services Criteria, supporting your organization's compliance and audit requirements.

About SOC 2

SOC 2 (System and Organization Controls) is a framework for managing customer data based on five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

Trust Services Criteria Coverage

Security (CC)

Information and systems are protected against unauthorized access.

Strong Coverage
Availability (A)

Information and systems are available for operation and use.

Strong Coverage
Processing Integrity (PI)

System processing is complete, valid, accurate, and timely.

Partial Coverage
Confidentiality (C)

Information designated as confidential is protected.

Strong Coverage
Privacy (P)

Personal information is collected, used, retained, and disclosed appropriately.

Strong Coverage

Common Criteria (CC) Controls

CC1 — Control Environment

Point of FocusATStatus Implementation
Demonstrates commitment to integrityHash-chained audit logs ensure data integrity
Exercises oversight responsibilityOWNER role with oversight of all users and settings
Establishes structure and authorityHierarchical RBAC with clear authority levels

CC2 — Communication and Information

Point of FocusATStatus Implementation
Generates relevant informationComprehensive audit logging, system monitoring
Uses internal communicationIncident updates, maintenance notifications
Uses external communicationPublic status page, subscriber notifications

CC5 — Control Activities

Point of FocusATStatus Implementation
Selects and develops controlsBuilt-in security controls (RBAC, 2FA, encryption)
Deploys through policiesConfigurable security settings, feature toggles
Uses technology controlsInput validation, rate limiting, CSRF protection

CC6 — Logical and Physical Access

ControlDescriptionImplementation
CC6.1Implements logical access securityRBAC, session management, authentication
CC6.2Registers and authorizes usersUser creation workflow, role assignment
CC6.3Removes access when no longer neededUser deactivation, session revocation
CC6.6Manages credentials for infrastructureAPI keys, environment variables, secrets management
CC6.7Restricts transmission of dataHTTPS enforcement, secure cookie configuration
CC6.8Prevents unauthorized softwareValidated dependencies, no dynamic code execution

CC7 — System Operations

ControlDescriptionImplementation
CC7.1Detects and monitors anomaliesAudit logging, system monitoring, self-test
CC7.2Monitors system componentsAutomatic service monitoring (25 types)
CC7.3Evaluates security eventsSeverity-based audit event classification
CC7.4Responds to security incidentsIncident management workflow, notifications
CC7.5Recovers from incidentsStatus updates, RCA documentation, resolution tracking

Availability Criteria (A)

ATStatus is fundamentally a status communication platform, with built-in availability features:

  • A1.1: Real-time service availability monitoring
  • A1.2: Automatic status updates from monitoring checks
  • A1.3: Maintenance window scheduling and communication

Confidentiality Criteria (C)

  • C1.1: Classification through permission system
  • C1.2: Protection through encryption and hashing

Privacy Criteria (P)

  • P1-P8: Cookie consent management
  • P4: Subscriber data collection with purpose
  • P6: Data deletion capabilities
  • P8: Data export for access requests

Audit Preparation

For SOC 2 Type II Audit

Type II audits examine controls over a period of time (typically 6-12 months). Start collecting evidence early using ATStatus's audit log export feature.

Evidence Collection Points

Evidence TypeATStatus LocationTSC Coverage
Access control configurationAdmin → Roles, Admin → UsersCC6.1, CC6.2
Authentication settingsUser profiles (2FA status)CC6.1
Activity logsAdmin → Audit Logs (export)CC7.1, CC7.2, CC7.3
Incident response recordsAdmin → Incidents (with RCA)CC7.4, CC7.5
Monitoring configurationAdmin → ComponentsA1.1, A1.2
System health checksAdmin → Self-TestCC7.2
Important

SOC 2 certification requires a third-party CPA firm audit. ATStatus provides technical controls and evidence — your organization is responsible for the complete compliance program and engaging auditors.