Skip to content
SOC 2 · AICPA TSC 2017

Your SOC 2 controls,
continuously mapped.

Blackfyre’s 55 auditors scan AWS, Azure, GCP and on-prem, then map every finding to the SOC 2 controls across the five Trust Services Categories — with weighted scoring and tamper-evident evidence. Open source, self-host free.

Coverage · illustrative

15

SOC 2 controls

9

Frameworks

3 + on-prem

Clouds

Free

Apache-2.0

The standard

What SOC 2 covers.

AICPA Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) for service-org controls.

Security (CC)

Common Criteria

CC1–CC9: control environment, communication, risk assessment, monitoring, control activities, logical & physical access, system operations, change management, and risk mitigation.

Availability (A1)

Availability

System availability commitments — capacity planning, backup, and recovery.

Confidentiality (C1)

Confidentiality

Protection of information designated confidential across its lifecycle.

Integrity (PI1)

Processing integrity

Complete, valid, accurate, timely and authorised system processing.

Privacy (P)

Privacy

Notice, choice, collection, use, retention, and disposal of personal information.

Blackfyre maps findings to the 15 SOC 2 controls it tracks · one of 9 frameworks in the platform.

How it works

From scan to audit-ready evidence.

The same pipeline that scores your SOC 2 posture also produces the artifacts an auditor asks for — no spreadsheet reconciliation. Blackfyre assesses and evidences posture; it never claims a certification on your behalf.

  1. 01 · Scan

    55 auditors enumerate real resources across AWS, Azure, GCP and on-prem — plus Prowler and Checkov / Semgrep / Bandit as containerised scanners.

  2. 02 · Map

    Every finding maps to the 15 SOC 2 controls it affects. A single misconfiguration can touch several controls at once — the mapping records each one.

  3. 03 · Score

    Weighted per-framework scoring rolls findings into a posture score you track as your team ships fixes — no spreadsheet reconciliation.

  4. 04 · Evidence

    Each result is written to a tamper-evident vault — SHA-256 integrity hash, S3 Object Lock, versioning — ready to hand to an auditor.

Illustrative vault record · shows the shape, not real data

Evidence vaultillustrative
integrity
sha256:d4a1…9c02
control
Security (CC)
storage
S3 Object Lock · versioned
pii
AES-256-GCM · field-encrypted
verify
auditor recomputes the hash

55

Auditors

15

SOC 2 controls

3 + on-prem

Clouds

SHA-256

Tamper-evident

Open source · Apache-2.0

SOC 2, mapped and evidenced.

Blackfyre is Apache-2.0 — self-host it free forever, or try the hosted option (early access). First findings and mapped SOC 2 evidence in about fifteen minutes locally. It assesses and evidences your posture; it does not certify compliance.

15

SOC 2 controls

9

Frameworks

55

Auditors

Free

Apache-2.0