Tudovu Compliance Corps
Keep audit preparation connected to engineering work. Everything in Security Garrison, plus founder-led SOC 2 guidance, the full policy suite, and control-mapped evidence. Your team keeps control of scope, risk, infrastructure changes, and policy approvals.
$25,000/year
Includes Security Garrison and founder-led SOC 2 consulting.
Agents draft. Your team decides.
-
Trigger
AWS drift, a scan finding, or a new deployment starts the work. Activated SOC 2 checks add context against your scoped controls.
-
Tudovu investigates and drafts a PR
Agents examine the context and propose a change in your repository, with the relevant SOC 2 controls identified. The pull request explains the work for review.
-
Your team reviews and merges
Your engineers decide whether to approve, request changes, or decline. A proposed fix does not authorize deployment.
-
Deploy and prepare the record
The approved merge proceeds through your deployment workflow and its gates. Evidence is recorded when checks run. Start checks manually in the app; scheduled checks require scheduling to be enabled for your environment. A merge alone does not trigger a re-check. Documentation updates are proposed for your approval; your team approves publication of evidence and documentation.
Your team retains deployment, policy, and publication decisions. Documentation is proposed for approval before it is published.
Founder-led guidance through preparation.
Work with the team on the decisions that checks and pull requests cannot make for you.
- Control scoping and selection of relevant SOC 2 Trust Services Criteria
- Gap assessment review and remediation prioritization
- Audit preparation and auditor walkthrough support
- Audit questions and response support
- Security questionnaire support for enterprise deals
Corps supports preparation and responses. Your independent auditor determines the audit outcome; scope, starting posture, and your team's approvals affect readiness.
Ten policies, grounded in your environment.
Drafts use the context of your infrastructure. Your team reviews and approves each policy and subsequent updates.
- Information Security Policy (master)
- Access Control & Identity Management
- Encryption & Data Protection
- Change Management
- Incident Response
- Business Continuity & Disaster Recovery
- Vendor / Third-Party Risk Management
- Data Retention & Disposal
- Acceptable Use & Security Awareness
- Risk Assessment & Management
Carry the approved work into the audit record.
Corps includes Garrison's findings reports, Reclaim Score, remediation log, security policies, architecture and data-flow documentation, and posture summary, plus the audit material below.
Control-mapped evidence
- Activated SOC 2 checks and evidence mapped to SOC 2 Trust Services Criteria
- Exportable control-mapped evidence library for auditor handoff
- Change history showing what changed, when, and who approved
- Access review records
- Logging configuration and monitoring evidence
Customer and auditor reviews
- Full SOC 2 policy suite
- Security questionnaire answers drafted from evidence
- Living Trust Center with approved policies, evidence, and questionnaire answers
- Evidence exports and handoff preparation
Evidence is recorded when checks run, not merely when a PR merges. Checks can be manually initiated in the app; scheduled runs depend on scheduling being enabled for your environment. Keep the PR approval trail alongside check results. Documentation updates are proposed for approval. Your team approves publication of evidence and documentation; evidence collection itself does not require a separate approval.
Framework visibility. SOC 2 preparation.
Selectable coverage views map checks to CIS AWS Foundations (40 checks), NIST 800-53 rev 5 (68), and ISO 27001:2022 (153). SOC 2 is the audit layer, with 165 of the 171 bundled checks mapped to the Trust Services Criteria and all 61 criteria pre-seeded. Mappings show technical coverage, not a complete compliance program, consulting engagement, or certification. Corps adds founder-led SOC 2 consulting and audit preparation. Full framework programs for CIS, NIST, HIPAA, FedRAMP, and StateRAMP are on the roadmap.
- CIS framework program Roadmap
- NIST framework program Roadmap
- HIPAA program Roadmap
- FedRAMP program Roadmap
- StateRAMP program Roadmap
Garrison's current CIS AWS infrastructure benchmark checks assess AWS configurations; they do not constitute a full CIS framework program. Partner-delivered penetration testing and pen test reports also remain on the roadmap.
Plan for 2–4 weeks of preparation.
The target is under 30 hours of your team's time, subject to scope and starting posture. This is a preparation plan, not a promised audit completion date.
Week 1
Configure access, review architecture, assess gaps, and draft the first policies and remediation PRs. Your team supplies context and access grants.
Week 2
Prioritize remediation, review the policy set, and collect control-mapped evidence. Your engineers review PRs and make policy decisions.
Weeks 3–4
Finalize approved policies and evidence, prepare auditor handoff, and support responses. Your team completes risk, access, and backup reviews.
In our own gap assessment, we remediated 231 findings in two days. That result describes our environment and gap assessment, not a completed SOC 2 audit or a customer guarantee.
Read our gap-assessment story