SOL
SKYE Standard
Skyes Over London LC
SS-SOC2-001 Companion Pack · Compliance Center
⬡ All Platforms ← SOL Home Open Companion Pack →
SKYE Standard · SS-SOC2-001

SOC 2 Posture.
Enforced. Documented.
Instantly Retrievable.

The SS-SOC2-001 Companion Pack is a complete, offline-first SOC 2 enforcement toolkit built on the SKYE Standard. Four compliance documents — Checklist, Evidence Index, Scorecard, and Exception Form — running entirely in your browser. No backend. No subscriptions. Just proof.

No Backend
No Login Required
Offline-First
Export JSON & CSV
Print-Ready PDF
Auto Posture Scoring
4
Companion Documents
5 TSC
Trust Service Criteria
0–5
Posture Scoring Scale
L2+
Production Gate
100%
Offline & Private
The Standard

What Is the SKYE Compliance Center?

SOC 2 posture is the provable state of readiness — showing controls are designed, operating, and backed by continuously retrievable evidence. The SS-SOC2-001 Companion Pack makes that enforcement consistent across teams and geographies, with zero infrastructure required.

📐

Built on the SKYE Standard

SS-SOC2-001 is a formal standard owned by the Skyes Over London LC Security & Trust Office. Every artifact maps to the standard's enforcement rules — no guesswork, no interpretation drift.

🔒

Local-Only, No Data Leaves

All edits save to your device via browser localStorage. No server receives your compliance data. Export a JSON snapshot any time and import it on another device to pick up where you left off.

Instant Evidence Production

The Evidence Rule is simple: if proof cannot be produced quickly, the control is treated as non-operational. This pack gives you the system to produce that proof — fast.

Four Documents

One Pack. Four Enforcement Artifacts.

Use them in order: Checklist → Evidence Index → Scorecard → Exception Form (as needed). Each exports to JSON and CSV; each has a print-ready branded PDF.

SS-SOC2-001A
📋 Compliance Checklist
Implementation Status

The master control list — mandatory domains and applicable modules. Capture implementation status (Not Started / In Progress / Implemented / Not Applicable) for every SOC 2 control. Export your status as JSON for posture submissions or auditor review.

SS-SOC2-001B
🗂️ Evidence Index
Receipts Binder

The proof binder. Log every piece of evidence — screenshots, logs, configurations, reports — with control mapping, artifact type, date, and reviewer. Export to CSV for auditor handoff. If it's not in here, it doesn't exist.

SS-SOC2-001C
📊 Posture Scorecard
0–5 Domain Scoring

Score each SOC 2 domain 0–5 against the SKYE tier framework. Auto-fail gates flag mandatory gaps that block production promotion. Aggregate score maps to a SKYE posture tier (Level 1–4). The single-page answer to "where do we stand?"

SS-SOC2-001D
🚨 Exception Form
Time-Bound Gaps

No permanent waivers. Every control gap gets a time-bound exception with a risk statement, compensating controls, remediation owner, end date, and validation method. The Exception Form is how you allow gaps without lying to yourself or your auditors.

Process

The Recommended Enforcement Flow

Run through the four artifacts in order every audit cycle. The output of each feeds the next.

📋
Checklist
Capture implementation status for every mandatory control
🗂️
Evidence Index
Log and link artifacts that prove each control is operating
📊
Scorecard
Score each domain 0–5, identify auto-fail gates, confirm SKYE tier
🚨
Exception Form
Document any gaps as time-bound exceptions with owners and end dates
Posture Confirmed
Export, print, and submit your full posture package
Posture Scorecard

Know Your Exact Posture Level — No Ambiguity

The Scorecard eliminates opinion from compliance. Each SOC 2 domain is scored 0–5 against defined SKYE criteria. Auto-fail gates fire on mandatory gaps. The aggregate maps directly to a production gate decision.

  • 🔴
    Level 0–1: Development-only. Block from production.
  • 🟡
    Level 2: Minimum for client-data systems. No auto-fail gates.
  • 🟢
    Level 3: Required for high-risk systems. Sustained cadence + full evidence.
  • Level 4: Continuous posture. Automated controls + real-time alerting.
Posture Scorecard — Live View
Security (CC) 4.2 / 5 Level 3
Availability (A) 3.8 / 5 Level 3
Confidentiality (C) 3.1 / 5 Level 2
Processing Integrity (PI) 3.0 / 5 Level 2
Privacy (P) 1.8 / 5 Auto-Fail
Aggregate Posture 3.18 Action Required
Production Gate ⛔ BLOCKED — Privacy auto-fail
Non-Negotiable Rules

The SKYE Enforcement Standard

These rules apply to every system handled by Skyes Over London LC. The Companion Pack is built to enforce them — not suggest them.

Rule What It Means Enforced By
Level 2 Minimum Systems handling client data must score Level 2+ average with no mandatory domain below 3 and no auto-fail gates triggered. Scorecard + Evidence Index
Level 3 for High-Risk High-risk systems must sustain Level 3: cadences current, minimal exceptions, full-period evidence, quarterly reviews complete. Scorecard + Checklist
Evidence Rule If proof cannot be produced quickly, the control is treated as non-operational — regardless of what the checklist says. Evidence Index
No Permanent Waivers Every gap requires a time-bound exception. No exceptions without an end date, remediation owner, and validation method. Exception Form
Evidence Index

Your Receipts Binder — Always Ready

The Evidence Index is where compliance becomes provable. Log every screenshot, log file, configuration export, report, and policy document against the control it satisfies. When an auditor asks, the answer is a CSV export — not a scramble.

  • 🗂️
    Control Mapping: Every artifact is linked to the exact SOC 2 control it evidences.
  • 📅
    Date + Reviewer: Each entry records who gathered it and when, maintaining chain of custody.
  • 📤
    CSV Export: Hand auditors a structured file — no manual reformatting required.
  • 🔁
    Reusable Structure: Same format every audit cycle so reviewers know exactly where to look.
Evidence Index — Sample Entries
CC6.1 — Access Controls Logged
CC6.3 — MFA Enforcement Logged
CC7.2 — Security Monitoring ~ Pending
A1.1 — Uptime SLA Evidence Logged
P3.1 — Privacy Notice Missing
Total artifacts 24 logged · 2 pending · 1 missing
Export → evidence_index_q1_2026.csv
Built For

Who Uses the Companion Pack

🏢

Security & Compliance Teams

Run the full enforcement cycle — checklist to scorecard — on a defined cadence. The pack gives you a standard format so nothing changes from cycle to cycle.

👨‍💻

Engineering & DevOps

Know your production gate status before pushing. The Scorecard answers "are we Level 2+?" without waiting for a compliance team review.

🤝

Prospective Partners & Auditors

Request a posture package from any SOL team or partner. The Companion Pack produces a standardized, printable output that speaks for itself.

Let's Go

Enforce Your SOC 2 Posture
Right Now — No Setup. No Login.

The SS-SOC2-001 Companion Pack opens in your browser in seconds. All four documents are ready to use. Your data never leaves your device.

← SOL Home ⬡ All Platforms