---
title: "Financial Services Compliance Evidence"
description: "SOC 2 Type II, PCI DSS 4.0, GLBA Safeguards, and NYDFS 500 as hash-chained evidence in your tenant, verifiable by your auditor without trusting the vendor."
url: https://policycortex.com/solutions/financial-services
sealed: 2026-09-02
amended: 2026-09-05
register: solutions/financial-services
records: 6
digest: sha3:ca830f5b0a48c75e2836e2d98961d0a3bed5244800957ad1f23c305c037520d1
---

# Audit-ready every quarter, not just year-end.

SOC 2 Type II / PCI DSS 4.0 / GLBA Safeguards / NYDFS 500

SOC 2 Type II, PCI DSS 4.0, the GLBA Safeguards Rule, and NYDFS 500 ask for continuous evidence, not a point-in-time attestation. PolicyCortex records what your cloud was, what changed it, and what machines were allowed to do, hash chained inside your tenant, so the evidence you hand your auditor each quarter can be recomputed rather than trusted.

[Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

Access is reviewed. Scope and onboarding are agreed with your team.

## What a financial regulator asks you to prove

A SOC 2 Type II report covers an observation window, not a day: the auditor wants to know a control operated throughout it. PCI DSS 4.0 scopes the cardholder data environment and, since March 31, 2025, its future-dated requirements are in force. The amended GLBA Safeguards Rule names specific safeguards each covered institution must maintain. NYDFS 500 requires an annual certification signed by the highest-ranking executive and the CISO. All four ask the same thing of a cloud estate: show the state, show the changes, show who or what had authority.

Audit preparation is the cost of not having that record. The evidence that a control operated on a date is either already written, or it is reconstructed from memory in the weeks before fieldwork.

- **fin.soc2**: Trust Services Criteria. The Type II window is a range of dates the record regenerates to, not a folder of screenshots.
- **fin.pci**: PCI DSS 4.0, twelve requirement domains. The cardholder data environment is a declared scope on every record.
- **fin.glba**: The amended Safeguards Rule. Each named safeguard maps to controls the record evidences.
- **fin.nydfs**: NYDFS 500. The annual certification, signed by the highest-ranking executive and the CISO, rests on records they can have recomputed.

## The evidence your auditor and QSA receive

Your CPA firm still issues the report and your QSA still assesses. What changes is what they are handed. Where each proof files:

- **CC6 · CC7 (SOC 2)**: Proof of state and proof of change: logical access and system operations as point-in-time records and an append-only change history, regenerable to any date in the observation window.
- **PCI DSS req. 1 · 3 · 8 · 10**: Network controls, stored account data protection, identity, and logging as records with the raw provider response attached. Requirement 10 is served by the chain itself.
- **GLBA Safeguards**: Access controls, encryption, change management, and monitoring safeguards evidenced from the same rows.
- **NYDFS 500.02 · 500.06**: The cybersecurity program and audit trail requirements, answered from an audit trail that cannot be edited without detection.
- **Machine actions**: Proof of agency: what any automated remediation was permitted to do before it ran, in the trust mode you set. GATED is the default.

## How an auditor verifies the record

For a Type II window the recomputation runs from the first capture in the observation period to the last, so the auditor confirms a control operated throughout it rather than on the day a screenshot was taken.

Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.

A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.

**Stated limit.** PolicyCortex is not an assessor and does not certify anything. It produces the records a compliance decision rests on; the assessor, the authorizing official, or the accountable official makes the determination. What is not connected is not observed, and the record says so. Control identifiers cite NIST SP 800-53 Rev 5, NIST SP 800-171 Rev 2, PCI DSS 4.0, SOC 2 TSC, ISO/IEC 27001:2022 and 45 CFR 164 as published.

## Access and scope for your observation window

Read-only onboarding runs inside your own accounts with the cardholder data environment declared within the agreed scope. Captured records establish an observation window that the auditor can recompute.

Request access so we can review your environment, evidence needs, and onboarding scope. After access is approved, read-only onboarding uses SHADOW mode inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. You hold the records and can recompute the chain yourself.

- **eval.mode**: SHADOW. Watch only; nothing executes.
- **eval.onboarding**: Access is reviewed. Scope and onboarding are agreed with your team.
- **eval.location**: Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
- **eval.egress**: None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
- **eval.after**: You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.

## Delivery, if you want the record stood up for you

Licensing does not depend on it, but a fixed-scope delivery engagement is available: thirty days, one agreed primary cloud environment, an evidence package built and defended through assessor review. The independent assessor makes the certification decision. No certification is guaranteed.

- **engagement.scope**: Thirty days. One agreed primary cloud environment.
- **engagement.outcome**: An evidence package built and defended through assessor review.
- **engagement.limit**: The independent assessor decides. No certification is guaranteed.

[Every term of the engagement, on its own page.](https://policycortex.com/engagement)

## Questions assessors and buyers ask

**Q: Does this replace our SOC 2 auditor?**
A: No. Your CPA firm still issues the report. PolicyCortex produces the evidence and the record of control operation they examine, as rows they can recompute rather than screenshots they have to trust.

**Q: What about the PCI DSS 4.0 requirements that became mandatory in 2025?**
A: PCI DSS 4.0's future-dated requirements have been in force since March 31, 2025. The cardholder data environment is a declared scope, and controls across the twelve requirement domains are evidenced as records your QSA can recompute.

**Q: GLBA Safeguards Rule, 2023 amendment?**
A: The amended Rule names nine specific safeguards each covered institution must maintain. Each maps to controls the record evidences: access control, encryption, change management, monitoring.

**Q: NYDFS 500 and state-level rules?**
A: NYDFS 500 maps directly. State-level financial rules typically reference SOC 2 or NIST CSF, which the same records serve.

**Q: Does PolicyCortex make us compliant?**
A: No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.

**Q: What happens when a collector is down?**
A: The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.

Hand the auditor rows they can recompute. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | OBLIGATION | cfd91f77d70f | 47f0110841ac |
| REC 0001 | EVIDENCE | 212d16a02242 | cfd91f77d70f |
| REC 0002 | VERIFICATION | 8c82d3bf0e8d | 212d16a02242 |
| REC 0003 | EVALUATION | 335597cdeea0 | 8c82d3bf0e8d |
| REC 0004 | DELIVERY | c2cda54fd0ab | 335597cdeea0 |
| REC 0005 | QUESTIONS | ca830f5b0a48 | c2cda54fd0ab |

Head sha3:ca830f5b0a48c75e2836e2d98961d0a3bed5244800957ad1f23c305c037520d1. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
