SOC 2 · AI-assisted development

SOC 2 asked how you review Copilot. A policy paragraph is not the packet.

Point-in-time senior audit of Copilot, Cursor, and Claude Code output for teams facing Type II fieldwork, enterprise questionnaires, or change-management evidence requests. Written findings in 5–10 business days. Same engagement as our AI Code Audit, framed for the SOC 2 question.

SOC 2 AI code audit: change-management evidence for Copilot, Cursor, and Claude Code

Assessors and enterprise buyers have stopped asking whether you use GitHub Copilot. They assume you do. They ask who reviewed AI-assisted changes, at what seniority, on which paths, and what you wrote down. Maxiom’s SOC 2 AI code audit is the same productized, point-in-time AI Code Audit, scoped to the evidence those questionnaires actually want: change management, logical access on tenancy and auth, vendor/OSS posture, and a dated findings report. Named engineer. Read-only access. Client code stays in your environment. This is not a SOC 2 Type II certification, not an audit firm, and not a scanner PDF marketed as oversight. SaaS teams often arrive from software engineering for SaaS. If the folder on the table is copyleft rather than CC-series language, start with AI-generated code licensing review.

2002
Founded
$100M+
Delivered
98%
Satisfaction

The problem

The questionnaire still says human-in-the-loop

That sentence described autocomplete. It does not describe a year of Copilot and Cursor merges. Assessors want who, seniority, paths, and a dated artifact.

Change management has no AI trail

Tickets close. PRs approve. Nobody can show a findings record for AI-assisted auth, billing, or tenancy changes. Type II requests notice the gap.

Scanners are being handed over as the review program

Green CI is hygiene. It does not judge tenant isolation against your product, and it does not sign the customer security review.

What the SOC 2-framed audit covers

Evidence a questionnaire can cite. Not a binder.

Every engagement is conducted by engineers with 10-plus years of production experience. Scope is agreed up front. We have shipped software since 2002, with $100M+ in contract value and 221+ clients. Clutch-reviewed. That is delivery history, not a Type II logo.

Change management evidence

Who reviews AI-assisted diffs, at what seniority, what they write down, and whether that trail would survive fieldwork

Logical access and tenancy

Authorization and isolation gaps assistants copy from the nearest file, especially on new endpoints

Vendor and assistant inventory

Approved vs prohibited tools, where they run, and whether source left the environment

OSS and licensing

Declared packages plus generated snippets a lockfile scan cannot see

Logging and monitoring on AI-touched paths

Whether the log, the retention story, and the code path agree

Written findings and debrief

Severity-ranked report, live walkthrough, remediation order. Named engineer.

Free resource

SOC 2 evidence checklist for AI-assisted code

A practical review list for teams shipping with Copilot, Cursor, and other AI coding tools. Covering security, architecture, compliance, and code quality.

Change management

  • Who reviews AI-assisted diffs, at what seniority, before merge
  • Whether Copilot, Cursor, or Claude Code output is identifiable in the trail
  • Overrides, exceptions, and what was actually written down
  • Evidence a buyer or assessor can attach, not a policy paragraph

Logical access and tenancy

  • Authorization edges assistants copy from the wrong local pattern
  • Tenant isolation on new endpoints generated from a user-id check
  • Secrets completed from .env.example into real values
  • Admin or role names that do not match the product

Vendor and OSS

  • Approved vs prohibited coding assistants in writing
  • Copyleft or incompatible licenses in generated snippets, not only lockfiles
  • Hallucinated packages that later resolved on a public registry
  • Whether client source left the environment via unapproved tools

Monitoring and evidence

  • Audit logging on the paths assistants actually touched
  • CI scanners treated as hygiene, not the review program
  • A dated findings report a Type II request can cite
  • A named engineer who did not also ship the same diffs

Is this right for you?

Type II fieldwork is on the calendar

The assessor asked how Copilot changes are reviewed. You have a policy PDF. You do not have a findings trail. You need the snapshot before they sample tickets.

An enterprise buyer sent the long questionnaire

Row 40 is AI coding tools. “Human in the loop” will not attach to the email. You need a dated report from someone who does not also ship the diffs.

SaaS growth outpaced review

Billing, tenancy, and SSO paths picked up Copilot velocity. Senior review did not. You need a bounded pass before the next SOC 2 window, not an open-ended retainer yet.

How a SOC 2 AI code audit works

Kickoff

  1. 01

    Align

    Scoping · 30 minutes

    We map which assistants are in use, which repos matter for SOC 2, and whether the trigger is fieldwork, a customer questionnaire, or both.

    • Copilot, Cursor, Claude Code, or mixed
    • In-scope systems and trust criteria language
    • Date on the calendar

    You get: agreed evidence scope

  2. 02

    Access

    NDA · read-only

    Least-privilege repository access. Proprietary source is not processed through external AI.

    • NDA before access
    • Read-only permissions
    • No third-party AI on client code

    You get: a bounded intake

  3. 03

    Inspect

    Senior review

    Change management, access, tenancy, OSS, and logging on the agreed AI-assisted scope.

    • Paths a Type II sample would actually hit
    • Severity-ranked findings
    • Language a GRC owner can reuse

    You get: findings, not a scanner dump

  4. 04

    Debrief

    Report · next step

    Written report, live walkthrough, and a clear split: what to fix before fieldwork vs what belongs on an oversight retainer.

    • Written findings report
    • Live walkthrough with engineering and GRC
    • Optional monthly oversight

    You get: a packet you can show an assessor

  • NDA signed before access
  • Read-only repository only
  • Senior engineers every time
  • Report in 10 business days

Frequently asked questions

What is a SOC 2 AI code audit?

A fixed-scope, point-in-time senior review of code produced or heavily assisted by Copilot, Cursor, Claude Code, or similar tools, written so a SOC 2 questionnaire, Type II request, or enterprise buyer can see who looked, what they found, and what to fix. It is the AI Code Audit engagement with SOC 2 evidence language.

Does Maxiom certify us for SOC 2 Type II?

No. We are not your auditor. We do not issue a Type II report. We produce engineering findings your assessor, GRC team, or customer can use as evidence of how AI-assisted code is reviewed. Certification remains with a licensed firm.

How is this different from the AI Code Audit page?

Same core engagement, deliverable, access model, and timeline. This page is the intent-led entry for teams searching SOC 2, change management, or Type II evidence specifically. The AI Code Audit page is the category landing. Both convert into the same senior audit process.

How is this different from Compliance Engineering?

Compliance Engineering designs controls into the product (access, logging, retention) so the next assessment has code-level evidence. A SOC 2 AI code audit is a snapshot of what AI already wrote. Buy the snapshot when a date is on the calendar. Buy compliance engineering when findings need to become architecture.

Will this satisfy the AI-coding questions on a customer security questionnaire?

It gives you a severity-ranked findings trail and a named engineer, which is what those questions are asking for. It does not replace your policies, your CI scanners, or your assessor. “Human in the loop” remains a process claim until you have artifacts.

Do you process our source through third-party AI during the audit?

No. Client code stays in client environments. Senior engineers inspect directly. We do not run proprietary source through external AI tools as part of the engagement.

How long does it take?

After NDA and read-only access, initial findings are typically shared within five business days, with full report and debrief commonly inside 5–10 business days depending on repository size and how much SOC 2 mapping you want in the write-up.

Can this cover licensing and copyleft as well?

Yes, as a pillar of the audit. If the only folder on the table is open source, use the licensing review landing. If the questionnaire mixes change management, access, and OSS, keep it on this page.

What if we need ongoing review after fieldwork?

Start with the snapshot. Move to AI Code Oversight when you will keep merging assistant output after the date. The report goes stale. That is not a reason to skip the snapshot.

We handle PHI. Is this the right page?

The inspection model is the same. The access model is not a generic SaaS review. Say PHI on the scoping call. Healthcare product work is Maxiom Labs (https://www.maxiomlabs.com/). HIPAA software development remains available on this site when the buy is a build, not a findings trail.

Need SOC 2 evidence for Copilot before the next sample?

Most audits deliver findings within 5–10 business days after access. Start with a 30-minute scoping call. We will say if we are not the fit.

  • NDA signed before access
  • Read-only repository only
  • Senior engineers every time
  • Report in 10 business days