Compliance-led cloud security

Get SOC 2-ready without the audit scramble.

Kavryn scans your cloud environment, maps findings to SOC 2 controls, collects evidence, and generates auditor-ready reports your team can act on.

  • 01Read-only cloud onboarding
  • 02SOC 2 CC6 + CC7 control mapping
  • 03Email & Slack alerts

Starting with AWS. Built for multi-cloud readiness.

Readiness overviewSOC 2 Type 1 · us-east-1
CC6 control coverage84%

28

Controls

240

Evidence

12

Open

S3 bucket allows public accessCritical
IAM user without MFAHigh
EBS volume not encryptedMedium
Readiness scankavryn — zsh
$

One read-only role, whole AWS stack

S3IAMEC2RDSVPCEKSCloudTrailEBSSecurity GroupsLambdaCloudWatchKMSS3IAMEC2RDSVPCEKSCloudTrailEBSSecurity GroupsLambdaCloudWatchKMS
The deliverable01

An auditor-ready PDF, generated for you

Control-by-control matrix, evidence appendix, remediation log, and exceptions register — the artifact your auditor signs off on.

SOC2-Type1-Readiness-Report.pdfPage 4 / 28

Section 2 — Trust Services Criteria

Common Criteria — Logical Access (CC6)

Audit window: 2026-04-01 → 2026-04-30 · Account: [REDACTED] · Region: us-east-1

Control
Description
Status
CC6.1
Logical access controls restrict access
Pass
CC6.6
Network boundaries protect resources
Open
CC6.7
Data-at-rest encryption with customer-managed keys
Open
CC7.2
Monitoring of system components
Pass
CC7.3
Security incidents are evaluated
Exception
Generated by Kavryn · SOC 2 Type 1 readiness · evidence hashes verifiedsha256:[REDACTED]
How it works02

Three steps from cloud to audit-ready

The fastest path from cloud findings to SOC 2 evidence your auditor, customer, and team can understand.

01

Connect your cloud account in minutes

Connect with scoped, read-only access. AWS is supported today, with additional cloud providers planned.

02

We map every finding to a SOC 2 control

Daily scans across identity, networking, compute, storage, and database resources. Each finding tagged with the Trust Services Criteria control it touches.

03

Hand the auditor the PDF

Control-by-control matrix, evidence appendix, remediation log, exceptions register. Regenerate any time the audit window moves.

What you get03

Everything an auditor asks for

Engineering-led, cloud-deep. The dashboard, scans, and policies all exist to produce one thing: the report.

01

Auditor-ready PDF report

The artifact you hand your auditor: control-by-control matrix, evidence appendix, remediation log, exceptions register.

02

SOC 2 control mapping

Every finding maps to one or more Trust Services Criteria controls. CC6 and CC7 first — ~80% of cloud-relevant SOC 2.

03

Continuous cloud scanning

Daily scans across supported cloud accounts, starting with AWS services like IAM, S3, EC2, RDS, Security Groups, VPCs, Lambda, EKS, KMS, and more.

04

Read-only cloud onboarding

Connect supported cloud accounts with scoped, read-only access. No agents, no write permissions.

05

Immutable evidence collection

Daily snapshots tied to controls. Audit-window views and an exception register with sign-off and expiration dates.

06

Cloud security policies

Prebuilt checks for public exposure, encryption, identity hygiene, access keys, network rules, backups, and database configuration.

07

Plain-English remediation

Console, CLI, and Terraform steps for every finding. Engineers fix; auditors see the log.

08

Email & Slack alerts

In-app, email, and Slack webhook notifications when control state changes or a critical finding lands.

09

Team collaboration

Admin / Member / Read-only roles, shared findings, and audit logs so your auditor and your team see the same truth.

Built for cloud teams04

Findings written for your stack

Generic CSPMs flag a misconfiguration. Kavryn explains why your auditor cares — in the language of SOC 2 controls and your cloud workloads.

Critical
s3://[REDACTED]-assets

S3 bucket allows public access

Bucket policy and ACL permit public reads. Fails SOC 2 CC6.1 (logical access controls) and CC6.6 (network boundary protection).

CC6.1CC6.6
High
iam:user/[REDACTED]

IAM user has no MFA enabled

Console user with privileged access is missing multi-factor authentication. Fails SOC 2 CC6.1 (logical access controls).

CC6.1
High
rds:[REDACTED]-prod

RDS instance is publicly accessible

Production database is reachable from the public internet. Fails SOC 2 CC6.6 (network boundary protection) and CC6.1 (logical access controls).

CC6.6CC6.1
High
sg-[REDACTED]

Security group allows SSH from 0.0.0.0/0

Inbound rule exposes port 22 to the entire internet. Fails SOC 2 CC6.6 (network segmentation) — auditors will flag any open management port.

CC6.6
Medium
vol-[REDACTED]

EBS volume is not encrypted

Attached volume stores data at rest without encryption. Fails SOC 2 CC6.7 (data-at-rest encryption).

CC6.7
Frameworks05

One framework, shipped end-to-end

We'd rather take SOC 2 Type 1 all the way to an auditor-ready report than half-support four frameworks. That's the only thing we sell today.

SOC 2 Type 1

Available at GA

Trust Services Criteria CC6 (logical access) and CC7 (system operations) — ~80% of cloud-relevant SOC 2 controls.

Not available today: other frameworks may follow once our first design partners are through their SOC 2 Type 1 audits. We'll only list a framework here when you can actually buy it.

Fit06

Who Kavryn is for — and who it's not

We'd rather lose a deal than sell the wrong product. Here is the honest scope.

Built for you if

  • Cloud-native startups and growing teams preparing for SOC 2
  • An enterprise customer, auditor, or security questionnaire is asking for cloud security evidence
  • You’re preparing for SOC 2 Type 1 or need a clearer cloud control-readiness view
  • You want the auditor-ready PDF, not another dashboard to babysit

Not the right fit if

  • Bootstrapped pre-revenue startups with no audit deadline
  • Teams that need full Azure or Google Cloud coverage today
  • Anyone shopping for a live security operations or incident-response platform
  • Buyers picking the cheapest CSPM — Security Hub and Prowler are free
Pricing07

Plans that scale with your audit

Pick a plan and billing cycle. You'll finish signing up in the app.

Next step08

Ready to get SOC 2-ready?

Tell us about your cloud footprint and your audit timeline. We'll come back with a scoped readiness plan.

Talk to us