AI Controls With Evidence Behind Them
Eight Trust Services Criteria mapped to agent-generated evidence, computed continuously and exported as a signed bundle when the auditor asks.
The Control Set Predates the Tooling
Your SOC 2 control set was designed around people, servers, and applications. AI coding agents are none of those cleanly: they act with a developer's permissions, at machine speed, across every repository that developer can reach.
Auditors have started asking how those agents are governed. The controls that answer that question are mostly ones you already have - logical access, monitoring, change management - applied to a surface that was not in scope when they were written.
Evidence Collected the Week Before
- Screenshot archaeology. Evidence is captured manually near the audit window and describes a point in time that has already passed.
- No AI-specific artifacts. Nothing in the current stack produces records of what AI agents accessed or executed.
- Unmonitored regressions. A control can lapse silently between audit cycles.
Trust Services Criteria, Mapped
- CC6.1
- Logical access controls - AI tool access logs, policy enforcement records, MCP allowlist enforcement
- CC6.6
- Logical access to external boundaries - egress classification and destination control
- CC6.7
- Restricting transmission of sensitive information - DLP findings and redaction records
- CC6.8
- Unauthorized software controls - browser extension risk classification and AI tool inventory
- CC7.1
- Detection of configuration changes - file integrity monitoring and AI Profile drift
- CC7.2
- System monitoring - real-time policy violation alerts via Slack, email, and webhook
- CC7.3
- Evaluation of security events - threat detections with severity and resolution status
- CC8.1
- Change management - versioned policy history and audited exceptions
And keeps it current
- Coverage recomputes continuously from live fleet data - proven, partial, or unproven per control
- Drift detection alerts when a proven control loses its evidence
- Signed bundles let the auditor verify provenance without trusting a screenshot
- One-click policy templates for SOC 2 map rule sets to the criteria they support
An Audit That Is an Export
- Which SOC 2 criteria have AI-specific evidence right now?
- What changed since the last review, and did any control regress?
- Who owns each control, and when did they last attest to it?
- Can we produce a verifiable evidence package the same day it is requested?

See Kraitos AIDR in Action
Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.
[email protected]kraitos.io