SOC 2 evidence as a byproduct — not a project.
Every change already flows through machine-legible chokepoints — content-addressed SCM, hermetic builds, a CRD control plane, federated tokens. fastverk reads that state directly and turns it into audit evidence. No seat fees, no manual collection, audit prep collapsed from weeks to a query.
The evidence already exists.
Traditional compliance tools bolt read-only agents onto a human-driven SDLC — and still leave you collecting evidence by hand, quarter after quarter. fastverk inverts that.
The platform is built so that every auditable action passes through a narrow, machine-legible chokepoint — a hermetic build, a merge through the readiness gate, a federated short-lived token, a checkpointed agent event. The evidence an auditor asks for is already emitted as a structured byproduct of how work happens. This plugin reads the control plane's own state — it doesn't 'integrate with' the SDLC — so fastverk replaces the compliance SaaS instead of decorating it.
It doesn't integrate with your SDLC. It reads the control plane that already is your SDLC.
Every chokepoint is an audit trail.
Each machine-legible seam a change flows through emits an immutable, content-addressed record — mapped to the control it satisfies and the live source an auditor can click back to.
| platform chokepoint | evidence produced | control | source |
|---|---|---|---|
| hermetic RBE build | build provenance — repo@sha → image digest | CC8.1 | BUILD |
| merge / forge webhook | change-management (HMAC-verified ForgeEvent) | CC8.1 | FORGE_PR |
| ArgoCD app-of-apps | config-drift self-heal, reconciled to git | CC7.1 | ARGOCD_APP |
| modgraph AccessPolicy | deny-by-default logical-access authz | CC5.2 | K8S_OBJECT |
| WorkloadGrant (OIDC) | short-lived scoped-token federation | CC6.1 | K8S_OBJECT |
| agent-events stream | attributed, replayable actor actions | CC1.1 · CC7.2 | AGENT_EVENT |
| HumanPrompt(approval) | who-approved-what, segregation of duties | CC5.2 | ATTESTATION |
| evidence store (S3 Object-Lock + KMS) | encryption + WORM — leading by example | C1.1 · CC6.7 | — |
Control posture, live.
A pure, deterministic evaluator maps evidence to each control and produces a status. Any conforming activity → SATISFIED; a nonconforming or partial one → EXCEPTION; no evidence → a gap. A gap shows as a gap.
| control | title | status | coverage | evaluated |
|---|---|---|---|---|
| CC7.1 | Detection of configuration drift | SATISFIED | 100% | 2m ago |
| CC2.1 | Internal control defined as code | SATISFIED | 100% | 5m ago |
| CC8.1 | Authorized, tracked, provenanced changes | EXCEPTION | 60% | 2m ago |
| CC6.1 | Logical access by identity & scope | NO EVIDENCE | 0% | 2m ago |
| CC6.7 | Encryption in transit and at rest | EXCEPTION | 80% | 5m ago |
| A1.2 | Backup and recovery | SATISFIED | 100% | 1h ago |
| C1.1 | Confidential information is protected | SATISFIED | 100% | 1h ago |
Every Trust Services Criterion, accounted for.
Common Criteria (Security) plus Availability and Confidentiality — the exact families in the 17-control catalog. Partial families are the honest, instrumented gaps that flip green as they close.
Evidence, the moment work happens.
Each collector writes a content-addressed EvidenceRecord (BLAKE3) into a write-once store the second the platform does something auditable. A digest is permanent, tamper-evident proof that never needs re-collecting.
One query, not a quarter.
GenerateAuditPackage assembles a point-in-time, content-addressed bundle — the system description, every ControlResult, and the evidence manifest — served as an immutable CDN artifact a CPA firm can verify by hash. Regenerating over the same period yields the same digest.
| field | value |
|---|---|
| framework | SOC2-2017 · catalog 2026.1 |
| controls | 17 evaluated · 13 satisfied |
| evidence | 1,204 records · content-addressed |
| manifest_digest | blake3:ee41…9c02 |
| artifact | static.fastverk.com/ee41…/soc2-typeII.zip |
Collectors → store → evaluator → package.
Four deterministic stages, each one auditable itself.
Collect
A CronJob + on-demand collectors harvest each chokepoint into immutable EvidenceRecords. A missing source degrades to NO_EVIDENCE — never a fabricated green.
Store
Every record is content-addressed (BLAKE3) and written once into an S3 Object-Lock (WORM) bucket with SSE-KMS. First write wins; re-collection is a no-op.
Evaluate
A pure, deterministic evaluator maps evidence to the Trust Services Criteria and produces a ControlResult per control — SATISFIED, EXCEPTION, or a gap.
Package
GenerateAuditPackage bundles the posture + evidence manifest into a signed, reproducible artifact. Same period + evidence → same digest.
SOC 2 today. The evidence remaps.
The control catalog is data (soc2.textproto) and the evidence is framework-agnostic — so more frameworks are a remap, not a re-collection.
| framework | status | controls |
|---|---|---|
| SOC 2 (2017) | ACTIVE | 17 · Type I & II |
| ISO 27001 | MAPPING | — |
| HIPAA | PLANNED | — |
| PCI DSS | PLANNED | — |
Evidence-first, not screenshot-first.
Legacy compliance-automation tools bolt read-only agents onto a heterogeneous, human-driven SDLC — and still leave you collecting evidence by hand. fastverk reads the control plane that produced the change.
A gap shows as a gap — never a fabricated green.
source · github.com/fastverk/plugin-compliance · tools: generate_audit_package
Prove it's safe to merge.
Compliance is one of 14 plugins in the fastverk console — hosted, or in your own cloud.