Compliance · SOC 2 Trust Services Criteria

SOC 2for agentic AI

The SOC 2 Trust Services Criteria that agent adoption touches, each mapped to the Speakeasy AI Control Plane capability that implements it.

14

Criteria mapped

The criteria agent adoption touches, from monitoring through confidentiality.

6

TSC series covered

From monitoring activities (CC4) to confidentiality (C1).

170+

Audit event types

Captured with per-call attribution and SIEM export, evidencing the mapped criteria.


01 · The mapping

Trust services, criterion by criterion

Series and criterion names follow the AICPA Trust Services Criteria. The capability column carries the same copy as the ISO 27001 mapping.

CC4

Monitoring activities

CC4.1Monitoring of controls

Captures more than 170 audit event types and redacted tool-call logs, with per-call attribution and SIEM export, so control operation is continuously evidenced.

CC6

Logical and physical access controls

CC6.1Logical access security

Issues every agent a revocable identity with scoped keys, and authorizes every tool call against toolset grants at the moment the agent acts.

CC6.2User registration and deprovisioning

Registers agents and enrolls devices against named users before credentials are issued, and revokes sessions, consents, and keys when authorization ends.

CC6.3Access modification and least privilege

Scopes access through roles and per-toolset grants separated by environment, with every grant change recorded as an audit event.

CC6.5Disposal of data and assets

Revokes sessions, consents, keys, and grants when an agent is decommissioned, with retention TTLs of 90, 400, and 730 days enforced automatically.

CC6.6Boundary protection against external access

Routes agent traffic through governed MCP endpoints and constrains egress to deployment-defined destinations.

CC6.7Restriction of information movement

Blocks secrets and PII from crossing the tool-call boundary with risk policies, storing detected values masked.

CC6.8Prevention of unauthorized software

Discovers unsanctioned MCP servers from live traffic and freezes tool lists to the approved snapshot, so upstream changes cannot inject new capabilities.

CC7

System operations

CC7.1Configuration and vulnerability monitoring

Versions agent configuration as append-only deployments, so drift from the approved capability surface is visible and reversible.

CC7.2Anomaly monitoring

Scans prompts and tool calls with Watchdog, scores findings by severity, and blocks spend past budget limits.

CC7.4Incident response

Contains a compromised agent through session revocation, policy flips to block, before-and-after audit snapshots, session transcripts, and deployment rollback lineage.

CC8

Change management

CC8.1Change management

Runs configuration changes through append-only deployments and approval workflows, with before-and-after snapshots on every state-changing update.

CC9

Risk mitigation

CC9.2Vendor and business partner risk

Records every MCP server as a supplier, with registry provenance, package metadata, and capability scoring for procurement review.

C1

Confidentiality

C1.1Protection of confidential information

Identifies confidential information in agent traffic with configurable detectors, redacts credentials in logs, and holds downstream secrets in encrypted environment stores.

02 · Certification

Certified and audited

The control plane meets the standards it helps you enforce. Audit reports and compliance documentation are available through the trust center.

Visit trust center

AI everywhere.

Control here.