SOC 2 readiness

SOC 2 readiness, backed by everyday evidence.

Bring identity, access, and device evidence into your SOC 2 preparation. Review findings, investigate saved reports, and build a clearer path to audit readiness.

Identity · Access · Offboarding · Devices

Evidence for your review

Start with evidence your team can explain.

Review access, investigate offboarding gaps, and identify devices that need attention. Saved reports preserve what was collected, where it came from, and where your team needs a closer look.

  • Review access with context

    Connect directory identities with observed accounts and permissions. Give reviewers a clearer picture of who has access and where account ownership needs investigation.

  • See where privilege lives

    Identify administrative access across supported connected systems, with evidence your team can use to review whether that access is appropriate.

  • Spot access left behind

    Highlight accounts and assignments retained by inactive directory identities so your team can investigate offboarding gaps.

  • Bring devices into the review

    Reconcile Intune inventory with Entra registrations. Surface stale check-ins, missing records, and reported security concerns for follow-up.

Ask Hyphen Agent

Your evidence. Your format. A smoother review.

Upload an example report, then work with Hyphen Agent to organize your collected evidence around its structure. You shape the explanations and level of detail in plain language, with references back to your saved reports.

During the meeting, you work directly with Agent to explore the data, clarify findings, and update your report in real time. Give your auditor or assessor updated information as questions arise, and work through follow-ups while you’re still in the room.

Criteria alignment

From evidence collection to repeatable reviews.

Hyphen connects recurring reviews, accountable owners, and approved changes with the records your team needs for SOC 2 preparation.

Hyphen capabilities and related Trust Services Criteria
Your SOC 2 priorityHow Hyphen helpsRelated Trust Services Criteria
Keep evidence currentRefresh evidence on a defined schedule, flag stale collections, and preserve review history so your team can follow changes over time.
  • CC2.1
  • CC4.1
Keep access accountableRoute access reviews to the right owners, record decisions and exceptions, and connect approved removals to follow-up evidence.
  • CC6.2
  • CC6.3
Find gaps in identity protectionHighlight MFA policy exclusions and authentication gaps across supported identity systems, with the context needed to investigate.
  • CC6.1
Keep configurations alignedCompare supported devices and workloads against approved security baselines, identify drift, and guide corrective action.
  • CC7.1
Make changes traceableBring the proposed change, approval, execution result, and verification evidence into one reviewable record.
  • CC8.1
Understand security activityConnect audit events across supported systems and help reviewers evaluate unusual activity with source-backed summaries.
  • CC7.2
  • CC7.3
Move findings toward resolutionGive findings an owner, track corrective work, and collect follow-up evidence so your team can verify the result.
  • CC4.2
  • CC7.1
Build documentation from evidenceHelp draft control narratives and operating procedures from collected evidence and recorded decisions, with your team reviewing and maintaining the final documentation.
  • CC2.1
  • CC5.3

These mappings connect Hyphen capabilities with activities related to the AICPA Trust Services Criteria. Coverage depends on connected systems, your controls, and examination scope. Your organization owns its controls; an independent CPA firm performs the examination and issues the SOC 2 report.

Frequently Asked Questions

How does Hyphen help with SOC 2 preparation?

Hyphen brings identity, access, offboarding, and device evidence into saved reports. Your team can review administrative access, investigate accounts retained by inactive identities, and identify device inventory gaps. Agent helps you ask questions about that evidence and follow the references behind the answers.

What can my team do with Hyphen?

Collect evidence on demand or on a schedule, assign reviews to owners, track approved remediation, and verify the results. Upload an example report and work with Agent to organize the evidence, refine your report, and give your auditor or assessor updated information during the review.

What does the Trust Services Criteria alignment mean?

The references show how Hyphen supports selected evidence gathering and operational activities related to the Trust Services Criteria. They do not mean Hyphen satisfies an entire criterion or covers every category. Your organization defines its controls and examination scope with its auditor.

How do Type 1 and Type 2 reports differ?

A Type 1 report evaluates control design as of a specified date. A Type 2 report also evaluates how controls operated throughout a specified period. Individual saved reports can support a review, but do not establish operating effectiveness throughout that period. Your team needs evidence appropriate to its controls and examination scope.

Can I use Hyphen reports during a SOC 2 examination?

Hyphen reports can provide supporting evidence for your preparation and auditor conversations. Saved reports preserve collected findings, references, and collection context so your team can explain what was observed and where coverage is limited. Your auditor determines the evidence and testing needed for the examination.

Does Hyphen automatically fix findings?

You control remediation. Hyphen connects findings to owners and recorded decisions, carries out supported changes with your approval, and collects follow-up evidence so your team can verify the results.

Does Hyphen issue my organization's SOC 2 report?

No. An independent CPA firm performs the SOC 2 examination and issues the report. Hyphen supports your preparation; your organization maintains its controls, system description, and supporting documentation.

How can I get Hyphen's own SOC 2 report?

Contact Hyphen for SOC 2 report availability, scope, and sharing requirements. Your organization's examination is separate from Hyphen's own.

Make SOC 2 preparation part of how you operate.

Start with a clearer view of identities, access, and devices. Give your team evidence they can review, explain, and build on.