FinOps SOC 2 — the audit trail is the product.
Tallywyrmis a 24/7 FinOps agent for multi-cloud spend. This page names the frameworks the audit trail already satisfies — SOC 2 Type II, ISO 27001 and FedRAMP Moderate — and how the data-handling decisions we already publish on /privacy back each one for cloud cost compliance.
The five trust-service criteria, covered end-to-end.
The audit trail we keep on /privacy already spans the weekly cadence your SOC 2 assessor runs against. The list below maps each criterion to the surface that satisfies it.
Every saving is attributable end-to-end — same audit trail the SOC 2 assessor runs against.
- Security — read-only credentials via the OIDC trust you already operate, scoped to the accounts you grant.
- Availability — hourly inventory and weekly audit pass documented in the service description on /terms.
- Processing integrity — every recommended change is traceable from inventory snapshot to merged PR to post-deploy measurement.
- Confidentiality — no write surface against billing, IAM, identity, or any control-plane service; same wording on /privacy.
- Privacy — inventory, audit events, and weekly report metadata covered by the retention windows on /privacy.
Annex A controls, risk treatment and the SOA.
Supplier-relationship controls are the ones buyers ask about first — the credentials are issued by you, brokered through your existing OIDC trust, not collected from the agent.
- A.5–A.18 control families — risk treatment, statement of applicability, and supplier-relationship controls bound the read-only credential scope.
- Risk treatment register — published alongside the SOC 2 trust-service-criteria posture this page covers.
- Supplier-relationship controls (A.15) — the cloud credentials are issued by you, brokered through your OIDC trust, not accepted from the agent.
- Statement of applicability — every Annex A control is either implemented by the platform or by your tenant on top of it, no exceptions hidden in the appendix.
Moderate baseline, continuous monitoring, US-region residency.
The control set your agency already audits against. Mapped through SOC 2 and ISO 27001 above; the cadence below is exactly what established assessors expect to see.
- Moderate baseline — the control set your agency already audits against, mapped through the SOC 2 + ISO 27001 posture above.
- Continuous monitoring — hourly inventory + weekly audit pass is exactly the cadence established control assessors expect to see.
- US-region data residency — inventory, audit events and weekly reports stay in US regions; cross-region replication is opt-in per workspace.
- NIST 800-53 mapping — implicit through the SOC 2 trust-service-criteria and ISO 27001 Annex A coverage; no separate attestation paper.
The credential contract and the audit-trail export, together.
Two surfaces back all three frameworks above: the read-only credential contract already on /privacy, and the weekly audit-trail CSV export finance and security teams reconcile against.
- Read-only scope against the granted accounts — same wording on /privacy and in the FAQ.
- Brokered through your existing OIDC trust, never long-lived static keys.
- No write surface — cannot write to billing APIs, IAM, identity, or any control-plane service.
- No organisation-admin or account break-glass role, no role escalation, no cross-account assume-role into resources you have not already federated.
Full contract and retention windows on /privacy.
PR diff, deploy timestamp, post-deploy measurement, credit applied — one CSV, one audit window.
- Each saving ties to a diff, a PR, a deploy timestamp and a post-deploy measurement — the same attribution schema the FAQ describes.
- Weekly CSV export of the most recent savings report available in the dashboard; one row per offender plus a summary header row, ready for Excel or Sheets.
- Audit verifications, audit diff and the report week are exported alongside the savings rows so the file is the same evidence pack finance and security teams already reconcile against.
- The retention window on /privacy is the same that bounds the export — 13 months minimum, configurable per workspace.
Frequently asked format on /faq.
Same badges as the landing page, /pricing, /privacy, /terms and /faq.
The audit trail we describe above is what these frameworks already demand — nothing on this page is a new attestation, it is a public restatement.
- SOC 2 Type II
- ISO 27001
- FedRAMP Moderate
- EU CSRD
- SEC climate disclosure
- GDPR