If you've ever gone through a SOC 2 audit, you know the drill. It’s weeks of screenshotting dashboards and chasing down evidence across some dozen tools, while hoping the auditor doesn't ask a follow-up question you can't answer. Fortunately, SOC 2 doesn't have to be that painful, especially if the tools you already use for security are generating the evidence for you as a byproduct of just doing their job.
That's what Aikido Security can do for application and cloud security. Here's how it maps to what SOC 2 actually asks for, and where it fits differently depending on whether you're pursuing a Type 1 or Type 2 report.
SOC 2 Type 1 vs. Type 2
The licensed CPA firm running your audit is evaluating your controls against whichever Trust Services Criteria you've scoped in. Security is the only mandatory category, but most companies add availability, confidentiality, or both (privacy and processing integrity are the other two categories). Ultimately, the categories a company chooses after security depend on its business needs.
The report type, SOC 2 Type 1 or Type 2, changes what type of evidence is needed:
- Type 1 is a point-in-time snapshot. The auditor checks whether your controls are designed appropriately as of a specific date. You're showing your system and proving that the controls exist and are configured correctly today.
- Type 2 covers a period (typically 3 to 12 months) and attests that controls operated effectively throughout that window. This is the harder one. You need continuous evidence in the form of logs, timestamps, and remediation histories. They have to prove that a control didn't just exist on day one but kept working on day 47 and day 214.
A lot of teams under-invest in Type 1 preparation because they can submit just a config screenshot and move on. But then they get blindsided by Type 2 because now the auditor wants the full trail and the screenshots don’t cut it. Tools that only help you produce a snapshot don't help much once you're maintaining a Type 2 report year over year.
Where Aikido fits into the Trust Services Criteria
Aikido consolidates SAST, DAST, SCA, secrets detection, container and IaC scanning, cloud posture management (CSPM), malware detection, and AI pentesting into one platform. That gives you a unified dashboard: one place to pull all your evidence from, with an SLA and remediation workflow built on top. Auditors want a coherent story of vulnerabilities getting found and fixed within defined timeframes, not six different exports frankensteined together with different timestamp formats.
A few of the controls where Aikido can help:
Logical access (CC6.1) and boundary protection (CC6.6)
Aikido's cloud checks flag missing MFA enforcement and misconfigured access controls, and its secrets detection continuously scans for exposed credentials across repos and infrastructure. CC6.6 addresses protection against external threats at the system boundary. Aikido's cloud posture rules flag network segmentation gaps and exposed services, giving you that evidence directly.
Data transmission and encryption (CC6.7)
Cloud and SAST checks verify encryption in transit (and commonly at rest, though you should confirm this with your specific auditor's interpretation), so you're not manually verifying TLS configs across every service before an audit.
Software integrity and malware (CC6.8)
Aikido’s dependency screening and malware detection gives you a live inventory of what's running and flags known-malicious or compromised packages. That directly addresses the "prevent or detect and act upon the introduction of unauthorized or malicious software" language in CC6.8.
Monitoring and vulnerability management (CC7.1/CC7.2)
Continuous scanning across SAST, SCA, containers, and DAST produces exactly the kind of sustained evidence a Type 2 auditor wants to see over the full audit period. SLA tracking (time-to-remediate against defined thresholds) creates a dated, exportable record. And while SOC 2 doesn’t explicitly ask for a pentest, it’s generally expected that orgs run pentests to ensure the controls hold up if faced with a real attack. Aikido’s AI pentesting deploys AI agents that act like real attackers, discovering and exploiting flaws across your apps, APIs, and infrastructure. The pentest reports show everything that was tested and the vulnerabilities found. And for ongoing testing, Aikido Infinite is continuous AI pentesting.
Change management (CC8.1)
Aikido's CI/CD gates and SCM security posture checks give you a built-in change-management trail with two control points. PR gating checks each pull request and fails it when newly introduced issues meet your severity threshold. Release gating applies the same logic to a build or release, so a commit that fails the threshold does not ship. You set the threshold yourself, anywhere from low to critical, and the gates cover dependency vulnerabilities, SAST, IaC, secrets, and malware issues. On GitHub, branch protection with required status checks makes a failed check block the merge. All PRs, gate decisions, overrides, and exceptions are logged and auditable.
Risk assessment (CC3.2)
Severity scoring and reachability analysis (checking whether a vulnerable function is actually reachable in your code versus just present in a dependency tree), CVE exploitability analysis, and AI pentesting that validates whether a vulnerability is exploitable in your environment all feed into a risk-based prioritization process. When exploitability analysis is enabled, the Aikido Agent reads how a vulnerable package is used in your repositories and containers. Every run is recorded in a history, and you can require human approval before any action applies. Auditors increasingly expect to see this rather than accept the "we patch everything eventually" story.
Availability (A1.2)
Cloud checks on backup integrity and completeness support the availability criteria, which sit outside the CC-series entirely as their own "A" criteria.
Getting ready for SOC 2
A dashboard showing vulnerability detection and remediation SLA adherence across the full audit window gives an auditor everything they need. Without that sustained view, you're looking at a back-and-forth email chain asking for "more coverage" of the period.
Of course, no tool by itself will pass your audit. Auditors will always want to see your policies, procedures, risk assessments, access reviews, and incident response process.
But Aikido handles the most tedious, evidence-heavy layer of SOC 2 and makes it exportable during audit season. Vulnerability management, access control verification, change management tracking, and encryption validation all live in one platform with one export path.
If you're pursuing Type 1 first with Type 2 as the near-term goal, set up the continuous scanning and SLA tracking early, even before the audit period officially starts. Evidence you didn't capture doesn't exist retroactively, and for Type 2, the clock on "operating effectively throughout the period" starts the day your auditor says it does.

