Converight — Immutable Conversation Compliance

SOC 2 Evidence Mapping

Evidence Converight can produce that you may use in support of your own SOC 2 controls. Whether a control is suitably designed and operating effectively is determined by you and your auditor.

Important: Converight has not completed a SOC 2 examination. Only an independent, appropriately licensed CPA firm may conduct the examination and issue a SOC 2 report. This page is informational and provides no audit, attestation, certification or readiness opinion.

Evidence Converight may provide in support of customer controls

Converight cannot cover your controls. What it can do is produce artefacts — exportable, timestamped, and in most cases tamper-evident — that you and your auditor may decide are useful. Which control each one supports, and whether it is sufficient, is your and your auditor’s judgement to make in the context of your own system.

AreaWhat Converight doesEvidence available
Data retention and disposalImmutable WORM archive with per-workspace retention policy and tested erasure pathRetention policy settings, retention sweep entries in the audit log
Logical access is logged and reviewableEvery human view, search, export and download of archived data is recordedExportable, hash-chained audit log
Backup and recovery of critical dataAutomated daily backups with alerting on any missed or failed runBackup run history with per-run item counts and status
Protection against unauthorised alteration or destructionS3 Object Lock prevents modification or deletion, including by Converight staffObject Lock mode and retain-until date shown on every archived record
Encryption of data at restPer-record envelope encryption; keys wrapped per workspacePer-record checksum and encryption metadata
Legal hold / preservation obligationsLegal Hold overrides all retention and erasure logicLegal Hold register with actor, timestamp, target and reason

Deliberately no Trust Services Criteria numbers. AICPA criteria evaluate control objectives in the context of a specific system and a specific auditor’s judgement, so a product feature does not map to one on its own.

What Converight produces no evidence for

Much of a SOC 2 examination is about your organisation rather than your archive — employee security training, vendor risk management, HR policy, change management. Converight produces no evidence for those.

For those, a compliance-automation platform such as Vanta, Drata, Secureframe or a licensed CPA firm is the right place to start. Naming them is a referral, not an endorsement or a partnership.

Asking for evidence

Most of the artefacts above are exportable from your dashboard. If your auditor needs something in a particular form, or you are completing a security questionnaire, email security@converight.com. Our compliance documents are indexed in the Trust Centre.