Access review evidence
Administrative accounts, role changes, session controls, MFA posture, and employee access should be reviewed and retained.
SOC2 readiness
Commandix is organizing security, availability, confidentiality, processing integrity, and privacy controls so enterprise buyers can review the system with a SOC2-style lens.
Trust services criteria
Enterprise buyers should understand which controls exist, which are process commitments, and which require auditor evidence before a report can be claimed.
| Criteria | Readiness focus | Commandix examples |
|---|---|---|
| Security | Protect systems and data from unauthorized access. | Authentication, authorization, tenant-aware access, HTTPS, HSTS, rate limiting, CrowdSec, logging. |
| Availability | Operate the service reliably and recover from disruption. | Health checks, infrastructure monitoring, backup and recovery review, incident process. |
| Confidentiality | Protect sensitive customer information. | Role controls, restricted access, secure transport, subprocessor review, confidentiality commitments. |
| Processing integrity | Process customer data accurately and predictably. | Validation, audit-oriented logs, workflow status, data integrity constraints, operational review. |
| Privacy | Handle personal data according to notice and commitments. | Privacy policy, cookie consent, rights intake, DPA overview, subprocessors, retention practices. |
Evidence plan
The strongest SOC2 program is not a frantic pre-audit cleanup. It is a habit of retaining proof that controls actually operate.
Administrative accounts, role changes, session controls, MFA posture, and employee access should be reviewed and retained.
Production changes should connect to code review, deployment history, rollback process, and issue tracking.
Security and availability incidents should show timeline, severity, containment, customer impact, and corrective action.
Subprocessors should be reviewed for necessity, risk, access to data, and contractual obligations.
Backup creation and restoration procedures should be periodically tested for enterprise readiness.
Security, privacy, acceptable use, access, and incident procedures should be versioned and reviewed.
This is a procurement starting point, not the end of diligence.
Request security answers, DPA review, subprocessor details, and deployment-specific configuration.
Confirm which controls are currently implemented and which are planned for formal audit readiness.
A pilot and an enterprise rollout may require different evidence depth and contractual language.
Send your questionnaire or control requirements and we will map them against the current Commandix posture.