Covered
The topic appears in enough surrounding language to look like a real statement, not a heading.
Free tool for small SaaS teams
Check your security policy before your SOC 2 audit.
Paste a policy and see which common policy elements are covered, which may need attention, and what you may want to review before your SOC 2 engagement.
Free · No account · No upload required
7 policy types · runs in your browser
This checker does not determine SOC 2 compliance, replace an auditor, or certify a document. Exact requirements depend on scope, Trust Services Criteria, your controls, and the independent auditor's examination. Companies do not need identical policy language.
Browser-side review
This is a deterministic checklist of common policy elements — not an AI audit and not an official AICPA tool.
Your policy is analyzed in your browser for this free check.
Processed in your browser. Your policy text is not required to leave this page for this free check.
Don't have a policy yet? Browse free SOC 2 policy templates.
It is a structured review of a written policy against common topics small SaaS teams document before a SOC 2 engagement. You paste text, the tool looks for coverage, and you edit. It is not fieldwork and not an attestation.
Governance details (owner, approval, dates, review, scope, roles, exceptions) plus topics typical for the policy type you select. Matches are phrase-based, with simple negation handling so “we do not require MFA” is not treated as MFA coverage.
The topic appears in enough surrounding language to look like a real statement, not a heading.
The idea is mentioned weakly, or placeholders still sit in that sentence.
No usable match after ignoring negated and instructional wording.
Whether you actually run the control, whether Type 1 or Type 2 is right, or legal sufficiency.
This version covers seven common documents for a first Security-focused program: information security, access control, incident response, vendors, change, risk, and business continuity / disaster recovery. Your auditor may ask for fewer, more, or combined policies.
A downloaded template with [Company Name] still in it describes a fictional company. Replace owners, systems, and cadences with what you do on a Tuesday. Then run this checker. Passing it still does not mean the policy is finished for an examination.
A policy is the written rule. A control is the practice — MFA on the IdP, the access-review export, the restore test. Auditors sample operation, especially for Type 2. Strong wording without evidence is still a gap.
Fix the missing sections that match how you operate, assign an owner, approve the document, and keep evidence that recurring controls ran. If you do not have a starting draft, use the template library. Then talk to an independent CPA firm about scope.
Related: SOC 2 for small SaaS teams, SOC 2 for startups, policy templates, SOC 2 checklist, readiness assessment, and AI compliance.
Yes. You can paste a policy, run the check, and see the full coverage review without an account or email.
Join early access if you want help turning gaps into drafts you can actually review — still with an independent auditor at the end.
SOC 2 · ISO 27001 · GDPR · and more