SOC 2 Type II - Final Review
44 turns · 8 min captured of 40 min stated?Only the captured portion exists in the database. The remaining 33 min of this call was never transcribed, so nothing said in it appears anywhere in this application.
Showing 44 of 44 turns · 30 turns were used as evidence for at least one fact.
- Ravi GuptaAegisCloud0:07turn 0ASR 90%
Alright, I think everyone's on — Diana, Nina, Tyler, you guys can hear me okay?
- Nina KowalskiAegisCloud0:14turn 1ASR 88%
Yep, loud and clear.
- Tyler WashingtonAegisCloud0:17turn 2ASR 90%
Good here.
- Diana ReevesAegisCloud0:19turn 3ASR 94%
I'm on, just grabbing my coffee real quick — okay, go ahead.
- Ravi GuptaAegisCloud0:24turn 4ASR 93%
Ha, same. Okay so, uh, really the reason I pulled everyone together today is we need to do a final walk-through of the SOC 2 Type II materials before we hand them off to the auditors, and honestly I'm — I'm feeling pretty good about where we landed.
- Nina KowalskiAegisCloud0:42turn 5ASR 93%
Yeah, I was looking at the Comply v2 exports this morning and I have to say, like, the on-demand reporting is just — it's night and day compared to what we were doing manually before.
- Tyler WashingtonAegisCloud0:55turn 6ASR 95%
Right? I remember we used to spend like two weeks pulling evidence packages together and now it's just... click, done.
- Diana ReevesAegisCloud1:02turn 7ASR 94%
I mean, that's genuinely what I'm going to tell customers when they ask about the April launch — like, this is the thing that changes the audit prep conversation completely.
- Ravi GuptaAegisCloud1:14turn 8ASR 95%
Totally agree. Okay so let me share my screen — give me one sec — alright, can everyone see the evidence package summary?
- Nina KowalskiAegisCloud1:22turn 9ASR 92%
Yep, got it.
- Tyler WashingtonAegisCloud1:25turn 10ASR 90%
Mhm, I can see it.
- Ravi GuptaAegisCloud1:27turn 11ASR 90%
So, the big sections are — availability controls, change management, logical access, and then incident response. And I want to walk through each one but I also, um, I want to flag the incident response section specifically because of the March outage.
- Diana ReevesAegisCloud1:43turn 12ASR 90%
Yeah, I was going to ask about that. How are we — how are we framing the Detect outage in the documentation?
- Ravi GuptaAegisCloud1:51turn 13ASR 93%
So that's actually something Tyler and I worked through last week, and I think we landed in a really good place — like, we're being fully transparent about the six hours of monitoring visibility loss, but we're also showing the complete remediation arc. Redundant nodes, the circuit breaker implementation, post-incident review docs, all of it.
- Tyler WashingtonAegisCloud2:11turn 14ASR 89%
Yeah and honestly, from a controls narrative standpoint, auditors typically respond well when you can show a clear before-and-after. Like here's the gap, here's what we did, here's the evidence that it's fixed. That's a mature posture.
- Nina KowalskiAegisCloud2:24turn 15ASR 92%
I completely agree with that framing. And Diana, from a customer-facing perspective, if this comes up in any account conversations, that's exactly the story — we identified a single point of failure, we fixed it comprehensively, and we have the audit trail to prove it.
- Diana ReevesAegisCloud2:41turn 16ASR 94%
Good, yeah. I'll be honest, I was a little nervous about how the auditors would receive that section but hearing you frame it that way, Tyler, that makes me feel a lot better.
- Ravi GuptaAegisCloud2:54turn 17ASR 90%
Yeah, I think we're in good shape. Okay, so let me jump to the logical access section — this is where Aegis Identity really shines in our own dogfooding. We've got full MFA enforcement documented, SSO logs going back the full audit window, access review records quarterly.
- Nina KowalskiAegisCloud3:11turn 18ASR 95%
Oh, and the deprovisioning logs — I want to make sure those are in there. That was a gap finding from our last Type I.
- Tyler WashingtonAegisCloud3:21turn 19ASR 92%
Yep, already in there. I specifically made sure of that. You can see it — section 4.3, employee offboarding workflow with timestamps.
- Nina KowalskiAegisCloud3:30turn 20ASR 93%
Oh nice, okay. Yeah that's — that's going to close out that finding cleanly.
- Ravi GuptaAegisCloud3:36turn 21ASR 93%
Good catch on that, Nina. Okay, change management — this one I'm most proud of honestly. We have full CI/CD pipeline logs, peer review approvals, the deployment freeze records from the March incident window. It's very complete.
- Diana ReevesAegisCloud3:50turn 22ASR 95%
Can I ask a quick question about the Comply v2 export format? Because I want to understand — when the auditor pulls this, is it like a static PDF or is it a live link?
- Ravi GuptaAegisCloud4:03turn 23ASR 92%
So it's — great question. The export is a point-in-time PDF with a hash for verification, but you can also generate a new one on demand if they want a refreshed snapshot. So it's not like a stale document sitting there.
- Diana ReevesAegisCloud4:18turn 24ASR 90%
Oh that's actually really elegant. Because the last audit we did, the auditor kept coming back with 'oh can I get an updated version of this' and it was just — it was painful.
- Tyler WashingtonAegisCloud4:31turn 25ASR 88%
Ha, yes — that's exactly the problem Comply v2 was designed to solve. Like, that pain point is the whole origin story of that feature.
- Nina KowalskiAegisCloud4:41turn 26ASR 94%
Okay, I want to flag one thing on availability — and this is minor, but I want to make sure we address it before submission. The uptime SLA documentation references 99.9% availability, but during the March window we were technically below that for Detect. Are we annotating that?
- Ravi GuptaAegisCloud4:58turn 27ASR 91%
Yeah, so — I'm glad you brought that up. We have a separate exception note with the incident report attached. Auditors expect exceptions to be documented, not hidden. And we actually came in above 99.9 for the full audit period across all other services, so the overall availability story is still very strong.
- Nina KowalskiAegisCloud5:18turn 28ASR 92%
Got it, okay. I just wanted to make sure it wasn't buried. As long as it's clearly cross-referenced I'm happy.
- Ravi GuptaAegisCloud5:26turn 29ASR 89%
It is, yeah. I'll send you the specific page reference after this call so you can verify.
- Diana ReevesAegisCloud5:34turn 30ASR 91%
Perfect. And can we talk about timeline? When are we actually submitting this to the auditors?
- Ravi GuptaAegisCloud5:40turn 31ASR 90%
So the plan is to get Nina's final QA sign-off by Wednesday, I'll do one last pass on the evidence package Thursday morning, and then we submit Thursday afternoon. Auditors have us in their queue for the week of April 27th.
- Nina KowalskiAegisCloud5:55turn 32ASR 93%
Wednesday is tight for me but doable. I just need to make sure I have access to the final Comply export — Tyler, can you make sure I'm provisioned on the reporting module?
- Tyler WashingtonAegisCloud6:08turn 33ASR 97%
Already done, actually. I added you this morning. You should have gotten an email.
- Nina KowalskiAegisCloud6:15turn 34ASR 89%
Oh! Yeah, I see it now. Okay great, that's super helpful, thank you.
- Ravi GuptaAegisCloud6:21turn 35ASR 94%
Awesome. Diana, from your side, is there anything the CS team needs from this package? Like, are there customer-facing commitments that are dependent on us getting the Type II cert?
- Diana ReevesAegisCloud6:32turn 36ASR 96%
Yes, actually — we have three enterprise prospects who've asked for SOC 2 Type II as a procurement requirement, and two existing customers who have it in their renewal terms. So getting the report by end of May is pretty critical for us commercially.
- Ravi GuptaAegisCloud6:48turn 37ASR 96%
Okay, that's helpful context. I don't think we're at risk on that timeline at all — if we submit Thursday and the audit window is the week of the 27th, we should have the report well before end of May.
- Diana ReevesAegisCloud7:02turn 38ASR 90%
That's a relief. I'll let those accounts know we're on track. Honestly, this whole process has been so much smoother than I expected — like, last year's audit was just a nightmare in comparison.
- Nina KowalskiAegisCloud7:16turn 39ASR 90%
Well, and that's honestly a credit to everyone on this call. Ravi, you've been driving this thing relentlessly, Tyler the technical documentation is rock solid, Nina your QA process caught things we would have been embarrassed to submit. It's just — yeah, it's been a good team effort.
- Ravi GuptaAegisCloud7:33turn 40ASR 94%
Aw, thanks Nina. Okay, I think we've covered everything — let me just recap the actions real quick: Nina signs off by Wednesday, I finalize Thursday morning, Tyler you're on standby for any last-minute evidence questions, and Diana you'll hold comms with the auditor contact. Everyone good?
- Tyler WashingtonAegisCloud7:50turn 41ASR 96%
Good with me.
- Nina KowalskiAegisCloud7:53turn 42ASR 96%
Yep, sounds great. Excited to get this across the finish line.
- Diana ReevesAegisCloud7:57turn 43ASR 95%
Same. Thanks everyone, this was a great call.