⚓ Running on beta — hold tight, things may still shake.

SOC 2 Trust Services Criteria

SOC 2 CC7.2 evidence, without the week-before-audit scramble

CC7.2 asks whether your organization monitors for security events and anomalies — including newly disclosed vulnerabilities affecting the systems you run — and evaluates what it finds. Auditors don't just want to hear that you do this; they want to see the record of it happening, on a schedule, over the period under review.

What auditors typically ask for

For a CC7.2 request, an auditor is usually looking for evidence that spans the full period, not a single point-in-time screenshot:

  • • A record of what was monitored — which threat intelligence sources, matched against which assets.
  • • Timestamped findings showing monitoring actually ran continuously, not just when someone remembered.
  • • A disposition for each finding — confirmed, ignored, or false positive — with who made the call and why.
  • • A sign-off closing out each review period, so there's a clear boundary between "reviewed" and "not yet."

A spreadsheet updated ad hoc technically contains this information, but reconstructing a clean, dated narrative from it a week before the audit is where most of the pain comes from.

How TrawlSec generates this evidence

TrawlSec monitors NVD, EUVD, and any custom feeds you point it at, matches findings against the assets you tell it you run, and routes anything relevant into a review queue. Every disposition is logged automatically with who, when, and why. Closing a review period locks that record in — and exports into a report scoped to the period an auditor is asking about.

No screenshots to take, no timeline to reconstruct from Slack and tickets after the fact — the workflow itself is the evidence.

See it before you sign up

The live demo has sample findings, a review queue, and a real generated PDF report — no account required.

View live demo