SOC 2 and the AIC Kits

Analog Informatics Corporation (AIC) kits include an auditing package. Audit records and the Assessment Binder are built in. The same records can feed a compliance package the organization already uses, such as Competitors. A licensed service auditor issues the SOC 2 report. The kits run in a secure enclave, air-gapped or generally connected.

Five distinct assurance pillars supporting a protected enterprise information archive
SOC 2 and the AIC Kits

What Availability Means

Trust Services Criteria

CriteriaWhat the Kit Does
CC1 Control environmentGovernance and oversight stay with the organization. The Assessment Binder stores the record.
CC2 Communication and informationTraining and attestation records that people received and signed policy material.
CC3 Risk assessmentCurrent State Compliance records findings. Risk decisions stay with the organization.
CC4 Monitoring activitiesContinuous configuration compliance monitoring and the Assessment Binder.
CC5 Control activitiesPrivileged access, least privilege, and approvals on kit paths.
CC6 Logical and physical accessLogical access through Privileged Identity Management, Privileged Access Management, and Privileged User Management. Physical access stays with the organization.
CC7 System operationsAudit, alerts, Incident Response, and continuous monitoring.
CC8 Change managementConfiguration compliance records the approved baseline and findings. Change approval workflow is planned.
CC9 Risk mitigationVendor and business risk stay with the organization. Incident Response supports response.
A1 AvailabilityCapacity and recovery stay with the organization. High-availability database failover is available on customer-supplied hosts.
C1 ConfidentialityValidated cryptography and the document sharing vault on kit paths.
PI1 Processing integrityInput validation and audit of privileged actions on kit paths.
P1 to P8 PrivacyAccount correction and removal in the kit. Notice, consent, and request handling stay with the organization.

Evidence feeds, partner tools, and migration help are on Partners and Migration.

Screenshots

A live security event feed shows sign-ins, configuration changes, and vault activity as they happen.

More on Product Screenshots.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.