SOC 2 and ISO 27001 readiness that shows its work

RedAssay works out readiness from the evidence your team collects, the policies you publish and who owns each control. When something slips, it names the task, policy or owner behind it.

RedAssay overview for Northwind Labs: SOC 2 about two-thirds ready, with a needs-attention list naming the controls whose evidence is overdue or missing.
Sample data. Northwind Labs is a fictional company.

From the first piece of evidence to a reviewer reading your policies.

  1. 01

    Every status comes with its reason

    A requirement at risk shows the date that slipped and the control behind it. Nobody types a status in.

    SOC 2 requirements filtered to at risk. Each shows why, such as evidence past its due date or no approved policy, and the controls mapped to it.
  2. 02

    Evidence can't be edited

    Each file or note is fingerprinted with SHA-256 when it's added. Deleting one leaves a record with the reason.

    The Review user access task with its evidence history: dated access-review exports and notes, each with a SHA-256 hash, and one deleted entry kept with its reason.
  3. 03

    Someone other than the author approves each policy

    Every change is a new version. It counts once it's approved and published, and goes at risk when its review date passes.

    Access Control Policy with draft version 1.2 waiting for approval, and its version history: 1.1 published, 1.0 superseded.
  4. 04

    Staff sign off from their phone

    Employees accept each policy version and finish five short training items. You see who hasn't.

    The employee portal on a phone: security checklist 4 of 7 done, one policy accepted and one waiting, and the first training items.
  5. 05

    Risks scored before and after treatment

    Likelihood by impact on a 5×5 matrix, with an owner, a treatment decision and the tasks that reduce each risk.

    Risk register with six risks, each with inherent and residual scores, category and owner, beside a 5 by 5 heatmap of residual risk.
  6. 06

    A trust center for your customers' reviewers

    Show your framework status and which policies you have. Reviewers ask for the documents, and you approve access for a set number of days.

    Northwind Labs' public trust center: security overview, SOC 2 in progress, and five policies available on request.
    The trust center's access form after sending: the reviewer is told a link will be emailed if the request is approved.

What it doesn't do

So you know before the call, not after.

  1. 01

    It doesn't certify you. The SOC 2 report or ISO 27001 certificate still comes from an independent auditor. RedAssay gets you ready for that audit and keeps you ready after it.

  2. 02

    It doesn't connect to your cloud accounts or scan infrastructure. Your team adds evidence by upload or note, and RedAssay tracks when each piece goes stale.

  3. 03

    It doesn't test your application. RedAssay's first product does that: an AI pentest agent, run as a service. Read about it at redassay.com.

Start with a call. We set it up with you.

We go through which frameworks you need, who will own the work, and what you already have.

What happens after you book

  1. 01

    The call. We agree your frameworks and owners, and note what you already have.

  2. 02

    Your setup link. A one-time link by email. It creates one organization and expires if unused.

  3. 03

    Your first day. Pick your frameworks. RedAssay creates controls, evidence tasks and policy drafts.