SOC 2 readiness, backed by everyday evidence.
Bring identity, access, and device evidence into your SOC 2 preparation. Review findings, investigate saved reports, and build a clearer path to audit readiness.
Identity · Access · Offboarding · Devices
Start with evidence your team can explain.
Review access, investigate offboarding gaps, and identify devices that need attention. Saved reports preserve what was collected, where it came from, and where your team needs a closer look.
Review access with context
Connect directory identities with observed accounts and permissions. Give reviewers a clearer picture of who has access and where account ownership needs investigation.
See where privilege lives
Identify administrative access across supported connected systems, with evidence your team can use to review whether that access is appropriate.
Spot access left behind
Highlight accounts and assignments retained by inactive directory identities so your team can investigate offboarding gaps.
Bring devices into the review
Reconcile Intune inventory with Entra registrations. Surface stale check-ins, missing records, and reported security concerns for follow-up.
Your evidence. Your format. A smoother review.
Upload an example report, then work with Hyphen Agent to organize your collected evidence around its structure. You shape the explanations and level of detail in plain language, with references back to your saved reports.
During the meeting, you work directly with Agent to explore the data, clarify findings, and update your report in real time. Give your auditor or assessor updated information as questions arise, and work through follow-ups while you’re still in the room.
From evidence collection to repeatable reviews.
Hyphen connects recurring reviews, accountable owners, and approved changes with the records your team needs for SOC 2 preparation.
| Your SOC 2 priority | How Hyphen helps | Related Trust Services Criteria |
|---|---|---|
| Keep evidence current | Refresh evidence on a defined schedule, flag stale collections, and preserve review history so your team can follow changes over time. |
|
| Keep access accountable | Route access reviews to the right owners, record decisions and exceptions, and connect approved removals to follow-up evidence. |
|
| Find gaps in identity protection | Highlight MFA policy exclusions and authentication gaps across supported identity systems, with the context needed to investigate. |
|
| Keep configurations aligned | Compare supported devices and workloads against approved security baselines, identify drift, and guide corrective action. |
|
| Make changes traceable | Bring the proposed change, approval, execution result, and verification evidence into one reviewable record. |
|
| Understand security activity | Connect audit events across supported systems and help reviewers evaluate unusual activity with source-backed summaries. |
|
| Move findings toward resolution | Give findings an owner, track corrective work, and collect follow-up evidence so your team can verify the result. |
|
| Build documentation from evidence | Help draft control narratives and operating procedures from collected evidence and recorded decisions, with your team reviewing and maintaining the final documentation. |
|
These mappings connect Hyphen capabilities with activities related to the AICPA Trust Services Criteria. Coverage depends on connected systems, your controls, and examination scope. Your organization owns its controls; an independent CPA firm performs the examination and issues the SOC 2 report.
Frequently Asked Questions
How does Hyphen help with SOC 2 preparation?
Hyphen brings identity, access, offboarding, and device evidence into saved reports. Your team can review administrative access, investigate accounts retained by inactive identities, and identify device inventory gaps. Agent helps you ask questions about that evidence and follow the references behind the answers.
What can my team do with Hyphen?
Collect evidence on demand or on a schedule, assign reviews to owners, track approved remediation, and verify the results. Upload an example report and work with Agent to organize the evidence, refine your report, and give your auditor or assessor updated information during the review.
What does the Trust Services Criteria alignment mean?
The references show how Hyphen supports selected evidence gathering and operational activities related to the Trust Services Criteria. They do not mean Hyphen satisfies an entire criterion or covers every category. Your organization defines its controls and examination scope with its auditor.
How do Type 1 and Type 2 reports differ?
A Type 1 report evaluates control design as of a specified date. A Type 2 report also evaluates how controls operated throughout a specified period. Individual saved reports can support a review, but do not establish operating effectiveness throughout that period. Your team needs evidence appropriate to its controls and examination scope.
Can I use Hyphen reports during a SOC 2 examination?
Hyphen reports can provide supporting evidence for your preparation and auditor conversations. Saved reports preserve collected findings, references, and collection context so your team can explain what was observed and where coverage is limited. Your auditor determines the evidence and testing needed for the examination.
Does Hyphen automatically fix findings?
You control remediation. Hyphen connects findings to owners and recorded decisions, carries out supported changes with your approval, and collects follow-up evidence so your team can verify the results.
Does Hyphen issue my organization's SOC 2 report?
No. An independent CPA firm performs the SOC 2 examination and issues the report. Hyphen supports your preparation; your organization maintains its controls, system description, and supporting documentation.
How can I get Hyphen's own SOC 2 report?
Contact Hyphen for SOC 2 report availability, scope, and sharing requirements. Your organization's examination is separate from Hyphen's own.
Make SOC 2 preparation part of how you operate.
Start with a clearer view of identities, access, and devices. Give your team evidence they can review, explain, and build on.