---
title: "SOC 2 and ISO 27001 Evidence for SaaS and AI"
description: "SOC 2, ISO 27001, and AI governance evidence for SaaS and AI companies selling to enterprise: hash-chained records, questionnaires answered from state."
url: https://policycortex.com/solutions/technology
sealed: 2026-09-02
amended: 2026-09-02
register: solutions/technology
records: 6
digest: sha3:77f3bae04fd3a820a4d91b0f8961cd435dc534b81547bc42c94b4c8981741854
---

# Sell to enterprise without the audit drag.

SOC 2 / ISO 27001 / OMB M-25-21 / NIST AI RMF

SaaS, platform, and AI companies close enterprise deals on their compliance posture, and the questionnaire asks what is true, not what the last report said. PolicyCortex records what your cloud was, what changed it, and what your models and agents were allowed to do, hash chained inside your tenant, mapped to SOC 2, ISO 27001, and the federal AI obligations.

[Request verification](https://policycortex.com/contact) · [Book a call](https://policycortex.com/book)

Read only. Fourteen days. No sales call required.

## What an enterprise buyer asks you to prove

A SOC 2 Type II report covers an observation window; an ISO 27001 certificate covers a scope statement; both are a year old the day the questionnaire arrives. The buyer's security team asks about now and about the interval since: is production encrypted, who has access, what changed, and, for products with models in them, which models and agents run in scope and what they are permitted to do. Government buyers add FedRAMP scoping, OMB M-25-21 AI inventories, and NIST AI RMF.

The audit drag is the gap between the last report and the answer. The record closes it: the questionnaire is answered from state as of today, and the auditor's window is a range of dates the record regenerates to.

- **tech.soc2**: Trust Services Criteria. Type I evidence exists from the first capture; Type II is the same rows across the observation window.
- **tech.iso**: ISO 27001 Annex A controls mapped to the same records; the scope statement is a declared boundary.
- **tech.ai**: Every model and agent in scope enumerated with identities, channels, egress paths, and binding envelope, as of a timestamp you choose. Exposure mapped against MITRE ATLAS.
- **tech.gov**: FedRAMP scoping when enterprise deals require government-side authorization; OMB M-25-21 and NIST AI RMF answered from the same records.

## The evidence a security questionnaire draws on

The questionnaire answered from state, the audit from the record. Where each proof files:

- **CC6 · CC7 · CC8 (SOC 2)**: Proof of state and proof of change: access, operations, and change management as point-in-time records and an append-only change history, regenerable to any date in the window.
- **Annex A 5 · 8 (ISO 27001)**: Organizational and technological controls evidenced from the same rows; the certificate scope is a declared boundary on every record.
- **AI estate inventory**: Every model and agent in scope with identities, channels, egress paths, and binding envelope. Shadow AI surfaces as a finding that closes only by claim-and-bind or removal on the record.
- **Machine actions**: Proof of agency: the envelope that permitted each autonomous action, the record of what it did, and the counterfactual that would have blocked it. Exposure mapped against MITRE ATLAS.
- **CI/CD**: Remediation proposals land where engineers work, gated for approval in the trust mode you set. GATED is the default.

![The PolicyCortex value report: engineer hours returned, controls satisfied, compliance posture, and the action queue](https://policycortex.com/images/pcx-platform-value-dashboard-1600.webp)

Exhibit SB-13 · engineer hours returned, controls satisfied, posture, and the action queue, every claim traceable to a record. Illustrative demo data; the interface is real.

## How a buyer's security team verifies the record

For an enterprise buyer the recomputation is the answer to the questionnaire's hardest question: the evidence behind each answer can be handed over and recomputed, including the inventory of models and agents in scope.

Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.

A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.

**Stated limit.** PolicyCortex is not an assessor and does not certify anything. It produces the records a compliance decision rests on; the assessor, the authorizing official, or the accountable official makes the determination. What is not connected is not observed, and the record says so. Control identifiers cite NIST SP 800-53 Rev 5, NIST SP 800-171 Rev 2, PCI DSS 4.0, SOC 2 TSC, ISO/IEC 27001:2022 and 45 CFR 164 as published.

## How you evaluate it between two reports

The fourteen days run inside your own tenant and include the AI estate inventory, so by the end the questionnaire can be answered from state as of today rather than from last year's report.

Connect read only for fourteen days, in SHADOW mode, inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. At the end of the fourteen days you hold the records and can recompute the chain yourself.

- **eval.mode**: SHADOW. Watch only; nothing executes.
- **eval.duration**: Fourteen days.
- **eval.location**: Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
- **eval.egress**: None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
- **eval.after**: You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.

## Delivery, if you want the record stood up for you

Licensing does not depend on it, but a fixed-scope delivery engagement is available: thirty days, one agreed primary cloud environment, an evidence package built and defended through assessor review. The independent assessor makes the certification decision. No certification is guaranteed.

- **engagement.scope**: Thirty days. One agreed primary cloud environment.
- **engagement.outcome**: An evidence package built and defended through assessor review.
- **engagement.limit**: The independent assessor decides. No certification is guaranteed.

[Every term of the engagement, on its own page.](https://policycortex.com/engagement)

## Questions assessors and buyers ask

**Q: Does this replace Vanta or Drata?**
A: It solves the same problem from a different angle. Vanta and Drata collect and monitor evidence you are shown. PolicyCortex produces evidence you can verify: hash-chained records of state, change, and machine authority that a second party recomputes, plus approval-gated remediation with a rollback identifier.

**Q: Type I or Type II?**
A: Both. Type I evidence exists from the first capture. Type II is the same rows across your observation window, regenerable to any date in it.

**Q: What do the federal AI obligations mean for us?**
A: If you ship AI features to government or regulated customers, OMB M-25-21 minimum risk management practices (deadline September 2026), the annual AI use-case inventory, and NIST AI RMF are answered from the AI estate inventory and proof of agency: which models and agents run in scope, what they are permitted to do, and what they did. PolicyCortex produces the records; the accountable official makes the determinations.

**Q: Can a small DevOps team run it?**
A: Yes. Deployment is infrastructure-as-code modules inside your tenant, and the fourteen-day evaluation is read only. Where you want it stood up for you, the delivery engagement is optional.

**Q: Does PolicyCortex make us compliant?**
A: No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.

**Q: Where does the data live?**
A: In your own tenant. There is no telemetry pipeline to PolicyCortex servers and no egress of evidence.

Answer the questionnaire from state, not from last year's report. [Request verification](https://policycortex.com/contact) · [Book a call](https://policycortex.com/book)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | OBLIGATION | a5d0a9d3dd9f | 8716853d60c6 |
| REC 0001 | EVIDENCE | 37bbb0e661a2 | a5d0a9d3dd9f |
| REC 0002 | VERIFICATION | cabe9b91d0ef | 37bbb0e661a2 |
| REC 0003 | EVALUATION | 9dce5e64d286 | cabe9b91d0ef |
| REC 0004 | DELIVERY | 29d7f83fc86f | 9dce5e64d286 |
| REC 0005 | QUESTIONS | 77f3bae04fd3 | 29d7f83fc86f |

Head sha3:77f3bae04fd3a820a4d91b0f8961cd435dc534b81547bc42c94b4c8981741854. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
