Open-Source Compliance Tool Automates SOC 2 Evidence Collection for Small AWS Teams
A Northeastern University student has built an open-source, customizable compliance automation tool aimed at small SaaS, fintech, and healthtech teams of 1–30 people using AWS and GitHub. The tool connects via AWS APIs to collect evidence, map it to compliance controls, and generate auditor-ready reports in under an hour. Unlike traditional black-box compliance dashboards, it uses SHA-256 tamper-evident chains of custody to make each evidence item verifiable by timestamp, control, and service. Users can create their own custom controls reflecting their company's unique policies and integrate them into the SOC 2 framework through a managed organizational workspace. The project was motivated by the developer's firsthand observation of manual compliance processes and broken automation tools wasting significant time for teams pursuing their first SOC 2 Type I audit.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in