Flintwood delivers automated monthly SOC 2 readiness reports for AWS environments — with a dedicated AI and agentic tool risk layer your auditor hasn't seen before.
Deploy a single read-only IAM role via CloudFormation or Terraform. We assume it monthly — nothing runs in your account.
Every finding maps to Trust Service Criteria: CC6 access controls, CC7 operations, CC8 change management, and more.
See exactly what changed: new gaps, resolved findings, regressions. Your readiness score trends over time.
Every report is reviewed before it reaches you. No raw scanner output. Context, severity, and prioritized remediation.
Every month we analyze your AI and agentic footprint: over-permissioned Bedrock roles, autonomous Lambda chains, unlogged model invocations, shadow AI usage, and more.
As your AI stack grows, so does your attack surface. Flintwood tracks it before your auditor asks about it.
Agent role bedrock-agent-prod has bedrock:InvokeModel on * with S3 write access and no MFA condition.
Bedrock model invocation logging is disabled. No audit trail for model calls in production.
3 Lambda functions with AI invocation permissions are not tagged as AI workloads.
We'll run a full scan of your AWS environment and deliver a SOC 2 readiness report — including AI risk findings — within 5 business days. No commitment.
Request pilot report →