SOC 2 reports
Extract control coverage, exceptions, carve-outs, complementary controls, scope, and period context.
Turn SOC 2 reports, penetration-test summaries, security questionnaires, and trust-center exports into documented controls, material gaps, follow-up questions, and a shareable decision.
This abbreviated example shows the vendor decision structure and omits parts of the complete interactive report.
SOC 2 + penetration test evidence · Completed today
SOC 2 evidence covers workforce MFA, but administrative support access needs confirmation.
Ask the vendor to commit to a customer-notification window.
Multiple documents can be included in one vendor review. The review is counted per vendor, not per document.
Extract control coverage, exceptions, carve-outs, complementary controls, scope, and period context.
Identify material findings, remediation status, testing scope, limitations, and unanswered questions.
Compare vendor claims with available documentation and identify statements that still need support.
The result is not a compliance certification. It is a structured review of what the submitted evidence supports and what it leaves open.
Add the SOC 2, penetration-test summary, questionnaire, trust export, or other authorized documents.
Identify covered controls, exceptions, missing information, risk signals, and conflicting claims.
Turn thin or missing evidence into explicit questions instead of unsupported positive assumptions.
Share the report, apply business context, and record the final approval, limitation, or rejection.
The report gives an auditor, client, manager, or procurement stakeholder the same control coverage, missing evidence, risk context, and final-decision basis your reviewer saw.
Vendor reviews support custom risk requirements and deal-breakers. Where evidence is thin, the report says so. CIRT does not turn missing vendor proof into a passing control.
Vendor documents can remain with the assessment for continuity. Customers decide whether to retain them.
Vendor documents remain with the assessment by default. Retention can be disabled, and the assessment plus retained documents can be deleted at any time.
All-inclusive submissions are not used for AI model training. BYOK processing follows the customer's Anthropic account settings and contract.
The review identifies incomplete evidence and follow-up questions rather than pretending the easy half of the vendor review is the whole decision.
Starter includes 2 vendor reviews per month. Multiple documents can be included in each review. Early-access BYOK vendor assessments have usually cost less than repository reviews in Anthropic usage, depending on document count.
The labor comparison is illustrative. Actual provider spend, review time, and organizational savings vary.
Upload the evidence, identify material gaps, and keep the final approval with your team.