SOC 2 Evidence Mapping
Evidence Converight can produce that you may use in support of your own SOC 2 controls. Whether a control is suitably designed and operating effectively is determined by you and your auditor.
Important: Converight has not completed a SOC 2 examination. Only an independent, appropriately licensed CPA firm may conduct the examination and issue a SOC 2 report. This page is informational and provides no audit, attestation, certification or readiness opinion.
Evidence Converight may provide in support of customer controls
Converight cannot cover your controls. What it can do is produce artefacts — exportable, timestamped, and in most cases tamper-evident — that you and your auditor may decide are useful. Which control each one supports, and whether it is sufficient, is your and your auditor’s judgement to make in the context of your own system.
| Area | What Converight does | Evidence available |
|---|---|---|
| Data retention and disposal | Immutable WORM archive with per-workspace retention policy and tested erasure path | Retention policy settings, retention sweep entries in the audit log |
| Logical access is logged and reviewable | Every human view, search, export and download of archived data is recorded | Exportable, hash-chained audit log |
| Backup and recovery of critical data | Automated daily backups with alerting on any missed or failed run | Backup run history with per-run item counts and status |
| Protection against unauthorised alteration or destruction | S3 Object Lock prevents modification or deletion, including by Converight staff | Object Lock mode and retain-until date shown on every archived record |
| Encryption of data at rest | Per-record envelope encryption; keys wrapped per workspace | Per-record checksum and encryption metadata |
| Legal hold / preservation obligations | Legal Hold overrides all retention and erasure logic | Legal Hold register with actor, timestamp, target and reason |
Deliberately no Trust Services Criteria numbers. AICPA criteria evaluate control objectives in the context of a specific system and a specific auditor’s judgement, so a product feature does not map to one on its own.
What Converight produces no evidence for
Much of a SOC 2 examination is about your organisation rather than your archive — employee security training, vendor risk management, HR policy, change management. Converight produces no evidence for those.
For those, a compliance-automation platform such as Vanta, Drata, Secureframe or a licensed CPA firm is the right place to start. Naming them is a referral, not an endorsement or a partnership.
Asking for evidence
Most of the artefacts above are exportable from your dashboard. If your auditor needs something in a particular form, or you are completing a security questionnaire, email security@converight.com. Our compliance documents are indexed in the Trust Centre.
