Sample compliance assessment
The owner-side deliverable behind the Trust Center: control-level results with evidence provenance, gaps, and remediation. No sign-up required — illustrative data.
Compliance assessment
Acme Commerce (Sample) — SOC 2 Type II
CT-1094 · completed June 1, 2026 · 25 controls assessed
Readiness
92%
Trust score
88
Passing
23/25
Gaps
1 partial · 1 failing
Control results (8 of 25 shown)
Okta SSO enforced org-wide; MFA required on all 14 accounts (IdP config read).
No shared credentials detected; GitHub branch protection + signed commits enabled.
Offboarding checklist exists; two contractor accounts remained active 9 days after end date.
Gap: Access revocation is manual and lagged HR offboarding twice in the last 90 days.
Remediation: Enable SCIM deprovisioning from the HR system to the IdP so departures revoke access automatically. (medium effort)
Sentry + UptimeRobot active; alert routing verified; 99.98% uptime over 90 days.
Incident triage process documented in runbook; last exercised during the March incident.
All production changes flow through reviewed PRs; direct pushes to main blocked.
No documented disaster-recovery plan or restore test found in connected sources.
Gap: Backups exist but restore procedures are undocumented and untested.
Remediation: Document a DR runbook and run a quarterly restore test; store evidence of the test run. (medium effort)
Code of conduct and security policy acknowledged by all staff in the HR system.
This is the owner’s working view. The public Trust Center shares only the positive summary — badges, scores, and verification timestamps — never gaps or remediation detail.
Run this on your own assets
CompTrail assesses SOC 2, GDPR, HIPAA, CCPA/CPRA, ISO 27001, and PCI DSS — continuously, with evidence provenance on every control.