Free for founding customers
SOC 2 readiness gap analysis
A free SOC 2 readiness gap analysis: a questionnaire mapped to the AICPA Trust Services Criteria, reviewed personally, returned as a written gap summary.
Important: This is a self-assessment gap analysis, not a SOC 2 audit, examination, or certification. It does not confer SOC 2 compliance and must not be represented as doing so. Only a licensed, AICPA-accredited CPA firm can perform a SOC 2 examination and issue a SOC 2 report. Converight is not a CPA firm and does not provide audit or attestation services.
Controls Converight already covers
Several of the controls a SOC 2 examination looks for are exactly what this product does. Where that is true, the gap analysis says so and points at the evidence you can already produce from your dashboard.
| Criterion | TSC | How Converight addresses it | Evidence available |
|---|---|---|---|
| Data retention and disposal | CC6.5 / P4.2 | Immutable WORM archive with per-workspace retention policy and tested erasure path | Retention policy settings, retention sweep entries in the audit log |
| Logical access is logged and reviewable | CC6.1 / CC7.2 | Every human view, search, export and download of archived data is recorded | Exportable, hash-chained audit log |
| Backup and recovery of critical data | A1.2 | Automated daily backups with alerting on any missed or failed run | Backup run history with per-run item counts and status |
| Protection against unauthorised alteration or destruction | CC6.7 / PI1.4 | S3 Object Lock prevents modification or deletion, including by Converight staff | Object Lock mode and retain-until date shown on every archived record |
| Encryption of data at rest | CC6.6 | Per-record envelope encryption; keys wrapped per workspace | Per-record checksum and encryption metadata |
| Legal hold / preservation obligations | CC2.3 | Legal Hold overrides all retention and erasure logic | Legal Hold register with actor, timestamp, target and reason |
Controls we will not pretend to cover
Gaps outside Converight’s scope — employee security training, vendor risk management, HR policy — are referred to a compliance-automation vendor or a licensed CPA firm rather than answered here.
For those, the analysis refers you to a compliance-automation platform such as Vanta, Drata, Secureframe, or to a licensed CPA firm for the examination itself. Naming them is a referral, not an endorsement or a partnership.
Request the analysis
Today this is delivered by hand: you complete a questionnaire mapped to the Trust Services Criteria, and get back a written gap summary. Capacity is limited to the founding customer cohort.