CVConverightBeta

Free for founding customers

SOC 2 readiness gap analysis

A free SOC 2 readiness gap analysis: a questionnaire mapped to the AICPA Trust Services Criteria, reviewed personally, returned as a written gap summary.

Important: This is a self-assessment gap analysis, not a SOC 2 audit, examination, or certification. It does not confer SOC 2 compliance and must not be represented as doing so. Only a licensed, AICPA-accredited CPA firm can perform a SOC 2 examination and issue a SOC 2 report. Converight is not a CPA firm and does not provide audit or attestation services.

Controls Converight already covers

Several of the controls a SOC 2 examination looks for are exactly what this product does. Where that is true, the gap analysis says so and points at the evidence you can already produce from your dashboard.

CriterionTSCHow Converight addresses itEvidence available
Data retention and disposalCC6.5 / P4.2Immutable WORM archive with per-workspace retention policy and tested erasure pathRetention policy settings, retention sweep entries in the audit log
Logical access is logged and reviewableCC6.1 / CC7.2Every human view, search, export and download of archived data is recordedExportable, hash-chained audit log
Backup and recovery of critical dataA1.2Automated daily backups with alerting on any missed or failed runBackup run history with per-run item counts and status
Protection against unauthorised alteration or destructionCC6.7 / PI1.4S3 Object Lock prevents modification or deletion, including by Converight staffObject Lock mode and retain-until date shown on every archived record
Encryption of data at restCC6.6Per-record envelope encryption; keys wrapped per workspacePer-record checksum and encryption metadata
Legal hold / preservation obligationsCC2.3Legal Hold overrides all retention and erasure logicLegal Hold register with actor, timestamp, target and reason

Controls we will not pretend to cover

Gaps outside Converight’s scope — employee security training, vendor risk management, HR policy — are referred to a compliance-automation vendor or a licensed CPA firm rather than answered here.

For those, the analysis refers you to a compliance-automation platform such as Vanta, Drata, Secureframe, or to a licensed CPA firm for the examination itself. Naming them is a referral, not an endorsement or a partnership.

Request the analysis

Today this is delivered by hand: you complete a questionnaire mapped to the Trust Services Criteria, and get back a written gap summary. Capacity is limited to the founding customer cohort.

Important: This is a self-assessment gap analysis, not a SOC 2 audit, examination, or certification. It does not confer SOC 2 compliance and must not be represented as doing so. Only a licensed, AICPA-accredited CPA firm can perform a SOC 2 examination and issue a SOC 2 report. Converight is not a CPA firm and does not provide audit or attestation services.