Skip to main content

SOC 2 Controls Mapping

This page maps CRAFT’s security controls to the SOC 2 Trust Service Criteria (TSC) 2017 (revised 2022) defined by the AICPA. CRAFT is the core platform powering the Emergence product suite. The mapping covers all five trust service categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
This mapping documents the platform’s built-in controls. Organizations pursuing SOC 2 Type II certification must also implement organizational controls (policies, procedures, training) and engage a qualified auditor.

Security (Common Criteria)

Security controls form the foundation of all SOC 2 categories.

CC6: Logical and Physical Access Controls

CC7: System Operations

CC8: Change Management

Availability

Backup and Recovery Controls

Processing Integrity

Data Integrity Controls

Confidentiality

Query result sensitivity inherits from the underlying data source. Healthcare data may be Restricted, while business analytics may be Confidential. Organizations must classify their data connections appropriately. See Data Classification for the full taxonomy.

Encryption Controls

Privacy

Access Review Controls

The platform supports periodic access reviews for SOC 2 compliance:
Administrators can review all RBAC grants per tenant using the Governance API. The review includes role assignments, last login timestamps, and permission inheritance paths.
Automated detection of agent registrations whose publisher account has been deactivated. Orphaned resources are flagged for review or ownership transfer.
Entities with no updates and consecutive failing health checks for a configurable number of days are flagged for review. Stale entities may indicate abandoned resources or decommissioned services.
When users are deactivated in the enterprise IdP, SCIM 2.0 sync automatically removes their Keycloak realm access and cleans up OpenFGA relations.

Evidence Collection

For SOC 2 audit evidence, the platform provides:

Next Steps

GDPR Compliance

Learn about GDPR-specific controls and Right to Be Forgotten.

HIPAA Compliance

Review HIPAA compliance considerations for healthcare deployments.

Authentication

Deep dive into the authentication architecture.

Data Classification

Review data classification levels and encryption standards.