Skip to content
SOC 2 Evidence

AI Controls With Evidence Behind Them

Eight Trust Services Criteria mapped to agent-generated evidence, computed continuously and exported as a signed bundle when the auditor asks.

The Situation

The Control Set Predates the Tooling

Your SOC 2 control set was designed around people, servers, and applications. AI coding agents are none of those cleanly: they act with a developer's permissions, at machine speed, across every repository that developer can reach.

Auditors have started asking how those agents are governed. The controls that answer that question are mostly ones you already have - logical access, monitoring, change management - applied to a surface that was not in scope when they were written.

What Goes Wrong Today

Evidence Collected the Week Before

  • Screenshot archaeology. Evidence is captured manually near the audit window and describes a point in time that has already passed.
  • No AI-specific artifacts. Nothing in the current stack produces records of what AI agents accessed or executed.
  • Unmonitored regressions. A control can lapse silently between audit cycles.
What Kraitos AIDR Does

Trust Services Criteria, Mapped

CC6.1
Logical access controls - AI tool access logs, policy enforcement records, MCP allowlist enforcement
CC6.6
Logical access to external boundaries - egress classification and destination control
CC6.7
Restricting transmission of sensitive information - DLP findings and redaction records
CC6.8
Unauthorized software controls - browser extension risk classification and AI tool inventory
CC7.1
Detection of configuration changes - file integrity monitoring and AI Profile drift
CC7.2
System monitoring - real-time policy violation alerts via Slack, email, and webhook
CC7.3
Evaluation of security events - threat detections with severity and resolution status
CC8.1
Change management - versioned policy history and audited exceptions

And keeps it current

  • Coverage recomputes continuously from live fleet data - proven, partial, or unproven per control
  • Drift detection alerts when a proven control loses its evidence
  • Signed bundles let the auditor verify provenance without trusting a screenshot
  • One-click policy templates for SOC 2 map rule sets to the criteria they support
What You End Up With

An Audit That Is an Export

  • Which SOC 2 criteria have AI-specific evidence right now?
  • What changed since the last review, and did any control regress?
  • Who owns each control, and when did they last attest to it?
  • Can we produce a verifiable evidence package the same day it is requested?
Compliance coverage view showing the gap between claimed and proven control coverage with a per-control grid
Control coverage - the gap between claimed and proven coverage, with every control resolving to the evidence behind it.

See Kraitos AIDR in Action

Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.

[email protected]kraitos.io