Comprehensive SOC 2 Type I/II compliance toolkit: trust service criteria checklists, control matrices, risk assessment templates, and audit preparation guides. By Petronella Technology Group.
-
Updated
Mar 6, 2026
Comprehensive SOC 2 Type I/II compliance toolkit: trust service criteria checklists, control matrices, risk assessment templates, and audit preparation guides. By Petronella Technology Group.
Example of GCP Landing Zone for US government agency — FedRAMP, NIST, SOC 2, SOX. Generated by Merlin Studio implements the Compiled AI paradigm: LLMs at build time, deterministic code at runtime.
TenableTrawler (Cloud OR FedCloud) is a Python project that pulls scan results via the Tenable API, laying them into organized, POAM-ready outputs. It supports various scans and exports in formats like CSV, JSON, and YAML.
MCP server for SCF Controls Platform — security compliance controls, frameworks, evidence, and risk management for AI agents
Reference GCP Landing Zone for US financial-services workloads — banks, payment processors, fintechs. Covers SOC 2, PCI-DSS, NIST 800-53, SOX with multi-region foundation. FAST-compatible. Generated by Merlin Studio implements the Compiled AI paradigm: LLMs at build time, deterministic code at runtime.
Patience - The Chat Bot Testing System
Multi-tenant AI SaaS platform for risk, culture, and communication management with LLM integration
Carbide (carbidesecure.com) is a compliance-automation and risk-management platform that pairs software with credentialed security advisors to help fast-growing organizations achieve and maintain security certifications and regulatory compliance.
Cloud Security Compliance Pipeline for AWS with automated multi-framework governance, Compliance-as-Code, Policy-as-Code and audit reporting using Python, Terraform, OPA/Rego and GitHub Actions.
Thoropass is an auditor-led, AI-powered compliance and audit automation platform that combines software with expert auditor services. Its products span continuous compliance monitoring and alerting, automated evidence collection, a global control library, vulnerability scanning, and CREST-accredited penetration testing, helping companies achieve…
Runloop is the AI Agent Accelerator — secure code sandboxes (Devboxes), evaluation infrastructure (Benchmarks, Scenarios), and production-grade orchestration for AI coding agents at enterprise scale.
Tugboat Logic is a security assurance and compliance automation platform acquired by OneTrust in 2021. It supports SOC 2, ISO 27001, HIPAA, GDPR, and NIST. As of 2024, the product has been rebranded under OneTrust's Certification Automation offering; legacy Tugboat Logic APIs are not publicly documented and integrations now flow through OneTrust's…
Exa is a neural web search API designed for AI agents and applications. It combines a purpose-built web index with embedding-based retrieval to deliver highly relevant results across categories such as full web, news, companies, research, people, and financials.
Synthflow is an enterprise-ready no-code Voice AI platform for automating phone conversations at scale. The product combines a visual agent designer with in-house telephony, sub-100ms latency, and a 99.99% uptime guarantee, so businesses can build, deploy, and operate voice agents without third-party carriers.
Drata is a continuous security and compliance automation platform supporting SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and more, with policies, evidence, and trust center. Drata exposes a public REST API plus the SafeBase Trust API (acquired) and a Custom Connections framework for evidence collection.
SOC 2 Type I and Type II compliance checklist - Trust Services Criteria with control mapping and evidence collection guide
Operator surface for multi-tenant B2B SaaS isolation posture: blast-radius classification, RLS/dedicated-schema/shared-prefix mapping, cross-tenant data-access audit, lateral-movement risk. Browser-only, no telemetry. AGPL-3.0.
Information Security and AI Governance resources covering ISO 27001, ISO 42001, NIST CSF, SOC 2, gap assessments, control mapping, and AI risk classification.
Scytale is an AI-powered Governance, Risk, and Compliance (GRC) platform that automates security compliance for cloud and SaaS companies. It combines AI agents with in-house compliance experts to automate evidence collection, continuous control monitoring, cross-framework control mapping, and audit-readiness across 80+ frameworks including SOC 2…
You.com runs an AI search and chat product alongside a developer platform that exposes web search APIs designed for AI systems, agents, and LLMs. The platform offers Search, Web Search, Contents, News, Smart, Research, and Finance Research APIs for grounding LLMs in real-time web data.
Add a description, image, and links to the soc-2 topic page so that developers can more easily learn about it.
To associate your repository with the soc-2 topic, visit your repo's landing page and select "manage topics."