SOC 2 Controls Mapping
This page maps CRAFT’s security controls to the SOC 2 Trust Service Criteria (TSC) 2017 (revised 2022) defined by the AICPA. CRAFT is the core platform powering the Emergence product suite. The mapping covers all five trust service categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy.This mapping documents the platform’s built-in controls. Organizations pursuing SOC 2 Type II certification must also implement organizational controls (policies, procedures, training) and engage a qualified auditor.
Security (Common Criteria)
Security controls form the foundation of all SOC 2 categories.CC6: Logical and Physical Access Controls
CC7: System Operations
CC8: Change Management
Availability
Backup and Recovery Controls
Processing Integrity
Data Integrity Controls
Confidentiality
Query result sensitivity inherits from the underlying data source. Healthcare data may be Restricted, while business analytics may be Confidential. Organizations must classify their data connections appropriately. See Data Classification for the full taxonomy.
Encryption Controls
Privacy
Access Review Controls
The platform supports periodic access reviews for SOC 2 compliance:User access reviews
User access reviews
Administrators can review all RBAC grants per tenant using the Governance API. The review includes role assignments, last login timestamps, and permission inheritance paths.
Orphan detection
Orphan detection
Automated detection of agent registrations whose publisher account has been deactivated. Orphaned resources are flagged for review or ownership transfer.
Stale entity detection
Stale entity detection
Entities with no updates and consecutive failing health checks for a configurable number of days are flagged for review. Stale entities may indicate abandoned resources or decommissioned services.
SCIM deprovisioning
SCIM deprovisioning
When users are deactivated in the enterprise IdP, SCIM 2.0 sync automatically removes their Keycloak realm access and cleans up OpenFGA relations.
Evidence Collection
For SOC 2 audit evidence, the platform provides:Next Steps
GDPR Compliance
Learn about GDPR-specific controls and Right to Be Forgotten.
HIPAA Compliance
Review HIPAA compliance considerations for healthcare deployments.
Authentication
Deep dive into the authentication architecture.
Data Classification
Review data classification levels and encryption standards.

