Readiness checklist
How AuditReady supports SOC 2 & ISO 27001 readiness
Use this as a working checklist with your auditor or as an answer sheet for vendor security questionnaires. AuditReady is the workspace that gets you audit-ready; a licensed auditor still issues the report.
Governance & frameworks
- SOC 2 Type II and ISO/IEC 27001:2022 control sets seeded on framework creation
- Each control carries a plain-English description, a named owner and a status
- Framework coverage is calculated from mapped policies and completed tasks
- Controls are versioned so historical state stays available for the auditor
Policies
- Policies authored in-app and mapped to the controls they satisfy
- Draft to review to approved lifecycle with an explicit approver
- Policy-to-control mapping surfaces uncovered controls before the audit does
- Approved policies are exportable as part of the per-framework audit pack
Access control
- Roles: owner, member and read-only auditor, assigned per organization
- Write actions gated by role on both the client and the server
- Auditor role can read controls, policies, tasks and evidence but change nothing
- Member management and plan changes require owner privileges
Tenant isolation
- Every record carries a tenant id; there are no shared rows between organizations
- Row-level security enforced in the database on every read and write
- Membership checks run through security-definer helpers, not client-supplied ids
- Cross-tenant reads return no rows rather than partial data
Evidence handling
- Evidence files stored in a private bucket under a tenant-prefixed path
- Downloads served through short-lived signed URLs, never public links
- Each file is linked to the control and task it proves
- Upload metadata records who submitted the evidence and when
Operations & audit trail
- Encrypted in transit and at rest
- Automatic session refresh and token rotation
- Tasks carry assignee, due date and status, with overdue work surfaced on the dashboard
- One-click per-framework export of controls, policies, tasks and evidence
AuditReady — compliance tracking for small tech teams. This document describes product capabilities and is not an attestation or certification.