SOC 2 testing evidence that covers the whole audit period
Hadrian tests your internet-facing systems continuously and runs agentic pentests on demand. Your team gets validated findings, fix history and pentest reports to support CC4.1, CC7.1 and related criteria.
A once-a-year pentest report no longer met partner expectations, so Aroma360 now shows continuous, validated testing, with automatic retests after fixes.
SOC 2 requirements Hadrian supports
SOC 2 is an attestation report from an independent CPA firm on a service organization's controls, assessed against the AICPA's 2017 Trust Services Criteria (with revised points of focus, 2022). A Type 2 report covers how those controls operated over a period of time.
Identify and analyze risks
Identify risks to your objectives across the organization and analyze them to decide how to manage them. This includes threats and vulnerabilities from vendors, business partners and others with access to your systems.
Hadrian gives your risk assessment an attacker's view of your internet-facing assets, with validated exposures ranked by likelihood of exploitation and business impact.
An exported asset inventory and validated risk list used as input to your risk assessment.
Evaluate whether controls are working
Run ongoing and separate evaluations to check that controls are present and functioning. A point of focus lists penetration testing among the evaluations management may use.
Atlas acts as an ongoing evaluation of your external controls by testing whenever your attack surface changes. Nova provides separate pentests on demand.
Nova pentest reports and dated continuous test results across the audit period.
Protect against threats from outside your boundary
Put logical access security measures in place to protect against threats from sources outside your system boundaries.
Hadrian tests your boundary from the internet and flags exposed services and misconfigurations. With the infostealer add-on, it also shows leaked credentials and session cookies tied to your domains.
Validated findings on boundary systems with remediation and retest status, plus leaked-credential records.
Detect configuration changes and new vulnerabilities
Use detection and monitoring procedures to find configuration changes that introduce new vulnerabilities, and susceptibility to newly discovered vulnerabilities.
Atlas starts new tests when an asset or its configuration changes, and Hadrian's hackers add coverage for new threats. Hadrian maps the Nova report to CC7.1.
Findings tied to the asset change that triggered them, with remediation and retest history.
Manage vendor and business partner risk
Assess and manage the risks that come from vendors and business partners.
Atlas shows the third-party technologies and services on your external attack surface and validates the exposures they introduce. Secure Share lets you send a risk to a vendor without giving them platform access.
A record of vendor-related exposures, who they were shared with and when they were closed.
Hadrian supports these criteria for your external attack surface. It does not certify or attest to SOC 2 compliance; your CPA firm does that.
Pentests on your schedule
Nova runs scoped pentests of web apps and APIs on demand, ahead of an audit window or after a release. Most tests finish within 24 to 48 hours. Hadrian's offensive security team validates every finding, and Hadrian maps the report to SOC 2 CC7.1.
Monitoring for new vulnerabilities between audits
CC7.1 looks for procedures that catch configuration changes and newly discovered vulnerabilities. Atlas runs new tests when your external attack surface changes, runs passive scans every hour, and only alerts on exposures it has validated.
A clear record of what you fixed
Each finding has reproduction steps, an owner and a risk timeline showing when it was found, shared, assigned and resolved. Hadrian retests after a fix, so the record shows the issue was closed.
More from customers
WeatherTech
WeatherTech had done compliance reporting by hand; it now exports an external risk report for partners in one click.
Breeze Airways
Breeze's lean security team gets findings already confirmed as exploitable, including API and Content Security Policy coverage.
No criterion requires one by name. Penetration testing appears in a point of focus under CC4.1 as one type of evaluation management may use, and points of focus are guidance. Agree the approach with your auditor early.
Nova reports are built to share with auditors. They include an executive summary, methodology, risk ratings, reproduction steps and remediation guidance, and Hadrian's offensive security team validates every finding. Hadrian maps the report to CC7.1. Your auditor decides what evidence is enough, so confirm their expectations on scope and tester independence. Where a framework or customer requires a named, certified tester, Hadrian recommends a traditional engagement alongside Nova.
A Type 2 report looks at how controls operated over a period. Atlas tests your external attack surface whenever it changes and keeps a dated record of what it found, who fixed it and when the retest passed. That gives you evidence across the whole period.
Yes. Hadrian completed a SOC 2 Type II audit, announced in February 2025. Hadrian is delivered as a cloud service with no agents or sensors to install in your environment.
No. Atlas and Nova test your external attack surface: internet-facing assets, web apps and APIs. Nova covers the OWASP Top 10 from an external perspective. Tests that need source code access or internal infrastructure fall outside the scope of an external pentest.
Go into your next SOC 2 audit with current test results
Book a demo to see how Atlas monitors your external attack surface, how a Nova pentest runs, and what the reports look like.