Skip to main content

SOC 2 Type II evidence map

Mapping from the SOC 2 Trust Services Criteria to the machine-readable evidence shipped by the AlphaSwarm overhaul.

This map is the artifact the compliance team hands to the auditor. It points at the source of truth for every control; the auditor can pull the evidence directly from S3 / CloudTrail / Postgres without manual collation.

CriterionControlEvidence sourceWhere in the repo
CC6.1 Logical accessAll API auth via IdentityProvidersecurity_audit_events Postgres + S3 WORM mirroralphaswarm/tasks/audit_log_export_tasks.py
CC6.1 (cont.)RBAC via Membership latticeMembership rows + expand_role latticealphaswarm_core/src/alphaswarm_core/auth/rbac.py
CC6.6 Step-up MFARFC 9470 step-up on every destructive admin routestep_up_denied rows in security_audit_eventsalphaswarm_admin/src/alphaswarm_admin/deps/stepup.py
CC6.7 Privileged accessBreak-glass 4-eyes + 60min auto-expiryadmin.break_glass.* audit rows + Security Hub findingsalphaswarm_admin/src/alphaswarm_admin/services/break_glass.py
CC6.8 CryptographyTLS 1.3 ingress + Linkerd mTLS internalALB security policy ELBSecurityPolicy-TLS13-1-2-2021-06; Linkerd identity certs from ACM PCAalphaswarm_platform/infrastructure/modules/acm-certificates, alphaswarm_platform/infrastructure/modules/acm-pca
CC7.1 DetectionFalco DaemonSet + custom rulesFalco events shipped to Lokialphaswarm_platform/deployments/kubernetes/helm/falco/values.yaml
CC7.2 MonitoringOpenTelemetry + Prometheus + Loki + TempoPer-env Grafana dashboardsalphaswarm_platform/infrastructure/modules/observability-stack
CC7.3 Incident responseKillSwitch fan-out + halt audit rowsadmin.halt.all rowsalphaswarm_admin/src/alphaswarm_admin/api/routers/halt.py
CC7.5 Threat intelTrivy + Grype on every imageBuild-time SBOM + provenance.github/workflows/build-publish.yml, .github/actions/build-sign-push/
CC8.1 Change managementHash-locked spec versionsterraform_stack_spec_versions, agent_spec_versions, bot_versions, rl_experiment_versions, analysis_spec_versions, workflow_spec_versionsper AGENTS rules 13/15/17/24/41/43
CC8.1 (cont.)Immutable Alembic migrations.hashes.lock + check_migration_immutability.pyscripts/ci/check_migration_immutability.py
CC9.1 Risk mitigationSLSA L3 provenance + Cosign keylessOCI attestations on every image.github/workflows/build-publish.yml
A1.2 Recovery proceduresDR replay runbook + Velero schedulesquarterly rehearsal logalphaswarm_docs/docs/operations/dr-replay.md
A1.3 Recovery validationCross-region S3 CRR + RDS read replicaLifecycle policies + replication metricsalphaswarm_platform/infrastructure/envs/prod/main.tf
C1.2 Confidential informationS3 Object Lock + KMS CMKalphaswarm-audit-archive-* bucket policiesalphaswarm_platform/infrastructure/envs/shared-services/main.tf
C1.2 (cont.)Step-up + RBAC on broker credsBrokerCredentialStore priority 4alphaswarm/credentials/stores/broker_credential_store.py
PI1.1 Processing integrityHash-chained audit_log table + Postgres triggertrigger enforce_audit_log_hash_chainalembic/versions/0079_audit_log_hash_chain.py
P1.1 Privacy noticen/a (B2B platform; no PII)n/an/a
P3.1 Information collectionOIDC scopes + https://alphaswarm.internal/resources claimAuth0 + Entra Action sourcesalphaswarm/auth/providers/

Type II evidence collection cadence​

CadenceActivity
ContinuousCloudTrail Org Trail, Config aggregator, GuardDuty, Security Hub findings; all S3 WORM-mirrored with 7-year retention
DailyAudit log export to WORM bucket (Celery beat 02:00 UTC)
WeeklyRenovate dependency updates merged to dev; SBOM diff review
MonthlyAccess review (operator-driven via /admin/rbac UI)
QuarterlyDR rehearsal per dr-replay.md; tabletop incident exercise
AnnualSOC 2 Type II audit window (12-month observation)

Operator hand-offs​

The platform team owns the controls; compliance owns the evidence collation + auditor liaison. The handoff is via the #alphaswarm-compliance Slack channel + the SOC 2 dashboard in Grafana (panels driven by Prometheus queries against security_audit_events).