SOC 2 & ISO 27001 Compliance

SOC 2 CC6 and ISO 27001 turn on access control. Your Linux fleet is where it lives.

CI/CD runners, service accounts, and SSH keys sprawl across production Linux faster than any manual review can track. Our pilot inventories the whole fleet — human and non-human — and produces the access-control evidence SOC 2 and ISO 27001 auditors test, so audit stops blocking deals.

Why SaaS & Technology Makes Linux Identity Visible

  • Non-human identities now outnumber humans by roughly 109 to 1 (Palo Alto Networks, 2026 Identity Security Landscape) — CI/CD runners, service accounts, and machine credentials on production Linux, most of them unowned and un-aged. SaaS fleets feel this ratio harder than anyone.
  • Cloud-fleet SSH key sprawl — reuse, stale keys, no inventory — maps directly onto SOC 2 CC6 and ISO 27001 A.8.2. The pilot builds a fleet-wide SSH key inventory graded by age, strength, and reuse.
  • Fast joiner/leaver churn produces orphaned production access, the classic SOC 2 de-provisioning finding. LinuxGuard surfaces accounts that should have been removed and the privileges they still hold.
  • LinuxGuard detects privilege and configuration drift on a 60-second interval using a lightweight, non-root eBPF-based agent designed not to slow production — continuous evidence without the overhead engineers push back on.
  • Audit is a sales blocker, not just a risk exercise: enterprise deals stall on SOC 2 and ISO 27001. Turning your Linux access evidence into an always-current artifact means audit enablement becomes deal enablement.

How the Founding Pilot Addresses SOC 2 & ISO 27001 Requirements

Every pilot finding is mapped to specific SOC 2 & ISO 27001 controls, providing direct compliance evidence for your regulatory submissions.

Scroll horizontally to see all columns →

Article / RequirementWhat It MandatesHow the Founding Pilot Covers It
SOC 2 CC6.1Logical access security — restrict access to authorized usersInventory of users, groups, sudo rules, and SSH keys across production Linux with privilege path mapping
SOC 2 CC6.2 / CC6.3Provisioning and de-provisioning of accessDetection of orphaned accounts and stale access from joiner/leaver churn on production systems
SOC 2 CC6.6Restrict privileged access and review itEvidence supporting privileged-access review, including sudo grants and non-human identity classification
ISO 27001:2022 A.5.15Access controlGovernance state of access control across the Linux fleet, risk-scored for remediation
ISO 27001:2022 A.8.2 / A.8.15Privileged access rights and loggingPrivileged-account and SSH-key assessment with audit-trail coverage for privileged actions

What You Get

  • Identity & Privilege Inventory — Every user, group, sudo rule, SSH key, and service account across your Linux estate, showing who can do what
  • Risk-Scored Findings Report — Prioritized findings based on real exploit patterns, highlighting the privilege paths attackers would use first
  • Compliance Evidence Package — Identity governance gaps mapped to SOC 2 CC6 and ISO 27001:2022 controls with remediation guidance
  • Prioritized Remediation Plan — Phased plan to reduce privilege drift and move toward least-privilege, with a zero trust alignment overlay where applicable
  • Board-Ready Executive Summary — Executive summary for boards and a technical deep-dive for your security team

How the Founding Pilot Works

The Founding Pilot runs in four phases over 60 days — discovery and scoping, identity and privilege mapping with lightweight read-only collectors, a security and compliance assessment that maps findings to SOC 2 CC6 and ISO 27001 controls, and reporting with a prioritised least-privilege remediation roadmap. See the Founding Pilot for the full four-phase process, timeline, and deliverables.

Frequently Asked Questions

Will this get us through our SOC 2 examination on its own?
No, and it is worth being precise: SOC 2 is an attestation issued by a CPA firm after an examination — there is no such thing as a "SOC 2 certificate", and LinuxGuard is not an auditor. What we produce is the access-control evidence a SOC 2 examiner actually tests: a current-state view of who holds privileged access across your Linux fleet, how SSH keys and service accounts are governed, and where the gaps are. That is what shortens your audit, not a certificate from us.
How does this map to SOC 2 CC6 and ISO 27001?
SOC 2 CC6 covers logical access — provisioning, de-provisioning, MFA, and privileged-access review — and ISO 27001:2022 A.5.15 and A.8.2 cover access control and privileged access rights. All of these resolve, on Linux, to sudo rules, SSH keys, and service accounts. We inventory those once and map each finding to the corresponding control in both frameworks.
We have thousands of service accounts and CI/CD credentials. Can you handle non-human identities?
Yes — this is where the pilot earns its keep for technology companies. Non-human identities outnumber humans by roughly 109 to 1, and most access reviews ignore them. LinuxGuard classifies non-human identities, grades credential age, and maps their privileges, so the service accounts and CI/CD runners driving your production fleet are inventoried alongside human users, not left as a blind spot.
Will the agent slow down our production fleet?
It is designed not to. The collector is lightweight, runs without root, and uses eBPF-based telemetry to observe the estate with minimal overhead. Drift is detected on a 60-second interval, giving you continuous evidence rather than a disruptive periodic scan — which matters when the systems in question are your revenue-generating production fleet.
How long does the SaaS pilot take?
The pilot is a fixed-scope engagement covering scoping and data collection, analysis mapping findings to SOC 2 CC6 and ISO 27001 controls, and delivery of the evidence package, executive summary, and remediation roadmap with a readout for your team. See the Founding Pilot page for the full timeline.

Ready to demonstrate SOC 2 & ISO 27001 readiness?

Request your SaaS-focused Linux identity pilot and receive the access-control evidence SOC 2 CC6 and ISO 27001 auditors test — so audit stops blocking deals.