Docs · SOC 2

Runtime evidence for the AI slice of your SOC 2 examination

Quantlix produces the runtime evidence for the AI portion of a SOC 2 audit — the gatewayed AI traffic a readiness platform cannot see. Quantlix cannot perform or issue SOC 2 reports; only a licensed CPA firm can attest under AICPA standards. Your auditor attests; Quantlix evidences.

A Type II examination samples controls across a real observation window — runtime evidence accrues in real time and cannot be backfilled. The window you can cover starts when the gateway does.

Nine criteria, honesty-tagged

The SOC 2 view of the obligations catalogue maps Trust Services Criteria to stored evidence. A criterion is tagged runtime-evidenced only when a stored field backs it; where the judgment is human, the tag says so — with an owner and a review date. This mapping is Quantlix's draft pending validation in live CPA fieldwork.

TSC CC6.1–6.3 · Logical access controls

Requires attestation

RBAC with discrete permissions, External Reviewer deny-list, access audit log, permission-gated exports — the access review itself is a human attestation, recorded with owner and review date.

TSC CC6.6–6.7 · System boundaries & transmission

Runtime-evidenced

Boundary enforcement on every gatewayed request; blocked-event records with rule, policy version, and timestamp — sensitive input stopped before the provider.

TSC CC7.1–7.2 · Monitoring & anomaly detection

Runtime-evidenced

One enforcement decision per gatewayed request; adversarial-input detections stored with violation codes; eval results stored in-product.

TSC CC7.3–7.5 · Incident management

Runtime + attestation

Blocked events and fail-closed deployment-stop audit records as inputs; the incident process is attested with owner and review date.

TSC CC8.1 · Change management

Runtime-evidenced

policy_version pinned to every decision; platform audit trail for lifecycle changes; applied-proposal provenance from decision to source clause.

TSC CC3 / CC9 · Risk assessment & vendor management

Requires attestation

Provider attribution and failover events as inputs; the programs are organizational judgments recorded as attestations.

TSC A1 · Availability

Runtime + attestation

Run records with status, provider failover events, deployment stop/resume records; SLO commitments and continuity plans are attested.

TSC PI1 · Processing integrity (AI calls)

Runtime-evidenced

A policy verdict on every gatewayed AI call; approval-gate decisions logged with actor identity and the request they apply to.

TSC C1 · Confidentiality

Runtime-evidenced

Redaction events as masked metadata (never message bodies); decision-level evidence-store retention; response caching opt-in, default off.

Outside the evidence scope — deliberately

SOC 2 scopes an entire service organization. Quantlix is one evidence source — the AI-runtime slice — not the readiness platform. These areas never appear as criterion rows, and their absence is stated in the product and printed in every SOC 2 bundle:

  • HR and personnel controls
  • Endpoint management
  • Physical security
  • Business continuity / disaster-recovery programs
  • Organization-wide vendor management
  • The Privacy category (P series)

The criterion-mapped audit bundle

A SOC 2 bundle adds a criterion-mapping section a CPA firm's workpapers can cite: for each criterion — reference, honesty tag, the bundle sections backing it, the evidence rows included in the bundle, and the attestation citation or its explicit gap. Counts state their basis on the artifact. The cover carries the CPA-boundary statement verbatim; CSV and PDF exports ship with the standalone verifier and JSON bundles embed the verification instructions — integrity confirmation requires no trust in Quantlix.

The AI-runtime slice of a Type II engagement

  1. External Reviewer access provisioned — scoped, time-boxed, read-only; audit-logged from day one.
  2. SOC 2 obligations map reviewed — which criteria carry live evidence, which carry attestations, which are out of scope.
  3. Evidence workspace queried — enforcement records filtered by period, verdict, rule, and deployment.
  4. SOC 2 audit bundle generated — framework-scoped, with the criterion-mapping section and the SOC 2 catalogue version stamped.
  5. Bundle verified independently — verify_audit_bundle.py confirms the manifest digest and Rekor anchors with no Quantlix account.
  6. The firm samples and attests — the judgment is the CPA firm's alone.

For audit firms: the attestation and the client relationship stay with the firm; Quantlix supplies the runtime evidence AI-heavy clients cannot otherwise produce. To discuss an engagement or a walkthrough: contact us.

Capabilities described as of August 2026. The criterion mapping is Quantlix's draft pending validation in live CPA fieldwork. Quantlix is not a CPA firm; this page is not an attestation, an audit deliverable, or legal advice. SOC 2 examinations and reports are performed and issued exclusively by licensed CPA firms under AICPA standards. Companion reference: EU AI Act readiness evidence.

SOC 2 Runtime Evidence — Quantlix — Quantlix