SOC 2 CC6 and ISO 27001 turn on access control. Your Linux fleet is where it lives.
CI/CD runners, service accounts, and SSH keys sprawl across production Linux faster than any manual review can track. Our pilot inventories the whole fleet — human and non-human — and produces the access-control evidence SOC 2 and ISO 27001 auditors test, so audit stops blocking deals.
Why SaaS & Technology Makes Linux Identity Visible
- Non-human identities now outnumber humans by roughly 109 to 1 (Palo Alto Networks, 2026 Identity Security Landscape) — CI/CD runners, service accounts, and machine credentials on production Linux, most of them unowned and un-aged. SaaS fleets feel this ratio harder than anyone.
- Cloud-fleet SSH key sprawl — reuse, stale keys, no inventory — maps directly onto SOC 2 CC6 and ISO 27001 A.8.2. The pilot builds a fleet-wide SSH key inventory graded by age, strength, and reuse.
- Fast joiner/leaver churn produces orphaned production access, the classic SOC 2 de-provisioning finding. LinuxGuard surfaces accounts that should have been removed and the privileges they still hold.
- LinuxGuard detects privilege and configuration drift on a 60-second interval using a lightweight, non-root eBPF-based agent designed not to slow production — continuous evidence without the overhead engineers push back on.
- Audit is a sales blocker, not just a risk exercise: enterprise deals stall on SOC 2 and ISO 27001. Turning your Linux access evidence into an always-current artifact means audit enablement becomes deal enablement.
How the Founding Pilot Addresses SOC 2 & ISO 27001 Requirements
Every pilot finding is mapped to specific SOC 2 & ISO 27001 controls, providing direct compliance evidence for your regulatory submissions.
Scroll horizontally to see all columns →
| Article / Requirement | What It Mandates | How the Founding Pilot Covers It |
|---|---|---|
| SOC 2 CC6.1 | Logical access security — restrict access to authorized users | Inventory of users, groups, sudo rules, and SSH keys across production Linux with privilege path mapping |
| SOC 2 CC6.2 / CC6.3 | Provisioning and de-provisioning of access | Detection of orphaned accounts and stale access from joiner/leaver churn on production systems |
| SOC 2 CC6.6 | Restrict privileged access and review it | Evidence supporting privileged-access review, including sudo grants and non-human identity classification |
| ISO 27001:2022 A.5.15 | Access control | Governance state of access control across the Linux fleet, risk-scored for remediation |
| ISO 27001:2022 A.8.2 / A.8.15 | Privileged access rights and logging | Privileged-account and SSH-key assessment with audit-trail coverage for privileged actions |
What You Get
- Identity & Privilege Inventory — Every user, group, sudo rule, SSH key, and service account across your Linux estate, showing who can do what
- Risk-Scored Findings Report — Prioritized findings based on real exploit patterns, highlighting the privilege paths attackers would use first
- Compliance Evidence Package — Identity governance gaps mapped to SOC 2 CC6 and ISO 27001:2022 controls with remediation guidance
- Prioritized Remediation Plan — Phased plan to reduce privilege drift and move toward least-privilege, with a zero trust alignment overlay where applicable
- Board-Ready Executive Summary — Executive summary for boards and a technical deep-dive for your security team
How the Founding Pilot Works
The Founding Pilot runs in four phases over 60 days — discovery and scoping, identity and privilege mapping with lightweight read-only collectors, a security and compliance assessment that maps findings to SOC 2 CC6 and ISO 27001 controls, and reporting with a prioritised least-privilege remediation roadmap. See the Founding Pilot for the full four-phase process, timeline, and deliverables.
Frequently Asked Questions
Will this get us through our SOC 2 examination on its own?
How does this map to SOC 2 CC6 and ISO 27001?
We have thousands of service accounts and CI/CD credentials. Can you handle non-human identities?
Will the agent slow down our production fleet?
How long does the SaaS pilot take?
Related solutions
The practitioner view — fleet-wide SSH key inventory, non-human identity classification, and sudo mapping that turn access reviews from a manual scramble into a continuous artifact.
Explore the Features
Zero-trust access controls and compliance posture for Linux infrastructure — the access-control evidence base your auditors test.
View Security & Compliance
One assessment, many frameworks — how a single Linux identity evidence set maps across the overlapping mandates a growing SaaS business accumulates.
View Regulated Industries
Further reading: Non-human identity on Linux — the 109:1 blind spot in access reviews.