Skip to content

SOC 2 — CC6.1 and CC6.8

Auditor-ready evidence for logical access controls.

We hold no SOC 2 attestation, and SOC 2 is not our certification track — ISO 27001 is. This page exists because a US buyer will ask in this vocabulary, and the honest answer is that the underlying controls are the same ones mapped for Annex A. Only the words differ.

CC6.1 — Logical access controls

Authorized access to protected resources

The action does not run until a human cryptographically approves it. The approval is the authorization event, not a record that one occurred elsewhere.

Identification and authentication of principals

Device-bound P-256 or FIDO2 with user verification required. INTYGA holds no private key capable of producing a valid approval.

Least privilege and separation of duties

A SERVICE identity can request but cannot approve. Four-eyes policy forbids self-approval, and the rule in force is frozen onto the challenge when it is created.

Hardware-class assurance

Individual actions can require an attested hardware authenticator by AAGUID, verified at approval time.

Accountability and non-repudiation

An append-only, Merkle-anchored ledger with the signer's payload, signature and public key on each client-signed event — independently verifiable with no INTYGA secret.

CC6.8 — Prevention of unauthorized execution

Prevention of unauthorized or malicious execution

Verification re-derives the canonical payload from the parameters about to execute and aborts if a single byte differs from what was signed. An approval for one action cannot authorize a different one.

Control of automated scripts and AI tools

Step-up policy intercepts tool execution over the control tunnel, so an agent's dangerous call is structurally unable to proceed without a human signature rather than merely discouraged from trying.

What your auditor can take away

The evidence export returns committed leaf preimages, per-entry inclusion proofs against a sealed checkpoint, and the per-tenant sequence commitment that makes an omission detectable. It is verified offline with the open-source verifier — no INTYGA secret and no trust in our word — and it is available on every plan, including the free one.

The control is checkable before the attestation exists.

You do not need our report to evaluate this. Take a receipt, verify it offline against parameters you construct yourself, and see whether the binding holds.

See the other framework mappings →