AuditReady
Back

Readiness checklist

How AuditReady supports SOC 2 & ISO 27001 readiness

Use this as a working checklist with your auditor or as an answer sheet for vendor security questionnaires. AuditReady is the workspace that gets you audit-ready; a licensed auditor still issues the report.

Governance & frameworks

  • SOC 2 Type II and ISO/IEC 27001:2022 control sets seeded on framework creation
  • Each control carries a plain-English description, a named owner and a status
  • Framework coverage is calculated from mapped policies and completed tasks
  • Controls are versioned so historical state stays available for the auditor

Policies

  • Policies authored in-app and mapped to the controls they satisfy
  • Draft to review to approved lifecycle with an explicit approver
  • Policy-to-control mapping surfaces uncovered controls before the audit does
  • Approved policies are exportable as part of the per-framework audit pack

Access control

  • Roles: owner, member and read-only auditor, assigned per organization
  • Write actions gated by role on both the client and the server
  • Auditor role can read controls, policies, tasks and evidence but change nothing
  • Member management and plan changes require owner privileges

Tenant isolation

  • Every record carries a tenant id; there are no shared rows between organizations
  • Row-level security enforced in the database on every read and write
  • Membership checks run through security-definer helpers, not client-supplied ids
  • Cross-tenant reads return no rows rather than partial data

Evidence handling

  • Evidence files stored in a private bucket under a tenant-prefixed path
  • Downloads served through short-lived signed URLs, never public links
  • Each file is linked to the control and task it proves
  • Upload metadata records who submitted the evidence and when

Operations & audit trail

  • Encrypted in transit and at rest
  • Automatic session refresh and token rotation
  • Tasks carry assignee, due date and status, with overdue work surfaced on the dashboard
  • One-click per-framework export of controls, policies, tasks and evidence

AuditReady — compliance tracking for small tech teams. This document describes product capabilities and is not an attestation or certification.