concept · compliancePublicVersion current

Planned SOC 2 evidence model

Use this page to understand the planned evidence families and the boundary between pre-attestation preparation and a completed attestation claim.

Scope

ClearPoint's SOC 2 Type 2 evidence program is planned and pre-attestation, with no committed completion date. Full attestation begins if and when a customer requires it; until then, ClearPoint pursues best-effort alignment with the standard. The public Trust Center status must come from the soc2_status claim category, with the current maturity qualifier kept on the same rendered claim line.

Trust boundary

This public page describes the planned evidence model. It does not expose customer records, restricted evidence artifacts, internal assessment details, or a customer-specific assurance result.

Control objective

The planned SOC 2 evidence canon maps ClearPoint controls to families such as governance, communication, risk management, monitoring, control activities, logical access, security operations, change management, vendor risk, availability, confidentiality, processing integrity, and privacy.

Data handled

The model refers to access, service-account, vulnerability, release, backup, audit, export, deletion, and retention evidence. Public wording names those families without publishing their restricted payloads.

Evidence produced

The source canon expects evidence from areas such as:

  • access reviews and tenant-boundary evidence;
  • least-privilege service-account review;
  • vulnerability scan and remediation evidence;
  • release, review, and CI evidence;
  • backup and restore review evidence;
  • audit event signature and chain verification evidence;
  • export, deletion, and retention request evidence.

Limitations

This page describes the planned SOC 2 evidence model and does not claim completed attestation. An evidence family or internal control record is not an attestation report.

Responsibilities

When attestation status changes, the public wording must be updated through the Trust Center claim_registry approval path before any docs page changes its maturity language.

Source

The authoritative source is the planned SOC 2 evidence canon identified by this page's source metadata. The live public status remains owned by the soc2_status claim category.

Next steps

Read the audit and evidence model for the material-action envelope or the security control model for the public control map.

Terms used on this page

Report a problem with this page

Do not include secrets or customer data.


Doc ID
cpl.docs.security.planned_soc2_evidence
Source
cpl-ops:docs/standards/platform-pack/CPL-SOC2-EVIDENCE-CANONICAL.md#5
Updated