What is a SOC 2 AI code audit?+
A fixed-scope, point-in-time senior review of code produced or heavily assisted by Copilot, Cursor, Claude Code, or similar tools, written so a SOC 2 questionnaire, Type II request, or enterprise buyer can see who looked, what they found, and what to fix. It is the AI Code Audit engagement with SOC 2 evidence language.
Does Maxiom certify us for SOC 2 Type II?+
No. We are not your auditor. We do not issue a Type II report. We produce engineering findings your assessor, GRC team, or customer can use as evidence of how AI-assisted code is reviewed. Certification remains with a licensed firm.
How is this different from the AI Code Audit page?+
Same core engagement, deliverable, access model, and timeline. This page is the intent-led entry for teams searching SOC 2, change management, or Type II evidence specifically. The AI Code Audit page is the category landing. Both convert into the same senior audit process.
How is this different from Compliance Engineering?+
Compliance Engineering designs controls into the product (access, logging, retention) so the next assessment has code-level evidence. A SOC 2 AI code audit is a snapshot of what AI already wrote. Buy the snapshot when a date is on the calendar. Buy compliance engineering when findings need to become architecture.
Will this satisfy the AI-coding questions on a customer security questionnaire?+
It gives you a severity-ranked findings trail and a named engineer, which is what those questions are asking for. It does not replace your policies, your CI scanners, or your assessor. “Human in the loop” remains a process claim until you have artifacts.
Do you process our source through third-party AI during the audit?+
No. Client code stays in client environments. Senior engineers inspect directly. We do not run proprietary source through external AI tools as part of the engagement.
How long does it take?+
After NDA and read-only access, initial findings are typically shared within five business days, with full report and debrief commonly inside 5–10 business days depending on repository size and how much SOC 2 mapping you want in the write-up.
Can this cover licensing and copyleft as well?+
Yes, as a pillar of the audit. If the only folder on the table is open source, use the licensing review landing. If the questionnaire mixes change management, access, and OSS, keep it on this page.
What if we need ongoing review after fieldwork?+
Start with the snapshot. Move to AI Code Oversight when you will keep merging assistant output after the date. The report goes stale. That is not a reason to skip the snapshot.
We handle PHI. Is this the right page?+
The inspection model is the same. The access model is not a generic SaaS review. Say PHI on the scoping call. Healthcare product work is Maxiom Labs (https://www.maxiomlabs.com/). HIPAA software development remains available on this site when the buy is a build, not a findings trail.