Parameter

[ SOC 2 penetration testing ]

Pentest evidence for SOC 2.From every release.

AI agents that find vulnerabilities in your web apps, APIs, and infrastructure. Continuously, so there is a dated test inside every observation period, not one from the year before.

See first findings in 24 hours

Built by the team that secured:

Apple
Google
Microsoft
U.S. Department of Defense
T-Mobile
Henkel
Epic Games
AT&T
Yahoo

[ what SOC 2 asks ]

What the criteria ask,and what a run gives you.

SOC 2 never says penetration test. Auditors ask for one anyway, because it is the cleanest evidence for these criteria.

5 covered by every run · 1 shared with your assessor

CC7.1 · Identify vulnerabilities

Procedures to identify new vulnerabilities and evaluate the system's susceptibility to them. A test on every release, with a report from each run, makes the process visibly continuous.

covered by every run

Evidence to keep: dated report per release

CC4.1 · Evaluate independently

Ongoing and separate evaluations of whether controls are present and functioning. A third-party test is stronger evidence than an internal one, and the agents sit outside your team, proving each finding with a working exploit.

covered by every run

Evidence to keep: the report, plus who ran it

CC7.4 and CC7.5 · Respond and recover

Identified vulnerabilities and incidents responded to and resolved. Each finding carries its proof, a fix, and a re-test on that fix, in the same report.

covered by every run

Evidence to keep: finding, fix, re-test, dates

Type II observation window

For Type I the test can fall any time in the 12 months before the report date. For Type II it has to happen during the audit period. Dated reports from every release cover both.

covered by every run

Evidence to keep: report dates inside the window

CC7.2 · Monitor for vulnerabilities

System components monitored for anomalies that indicate vulnerabilities or new threats. Continuous testing is monitoring made concrete: a run per release, with what it found.

covered by every run

Evidence to keep: the run history

The opinion itself

Whether your controls meet the criteria is the auditor's judgement. Parameter supplies the testing evidence; the service auditor issues the report.

shared with your assessor

Evidence to keep: none; this is the auditor's

[ how it works ]

Connect

A repository, a URL with test accounts, or a read-only cloud role. Testing starts within hours. No scoping call, no engagement to book.

Test every release

Agents test the running app, the code behind it, the cloud it runs on, and the packages it depends on, as different users, every time you ship. Every finding is exploited before it is reported.

Hand over the run

Each run produces a report with scope, method, findings, proof, and remediation status. Re-tests happen on fix, so the evidence is never older than the last release.

[ definition ]

Does SOC 2 require a penetration test?

Not by name. SOC 2's Trust Services Criteria ask you to identify vulnerabilities (CC7.1), evaluate your controls independently (CC4.1), and act on what you find (CC7.4). A penetration test is the evidence auditors expect for all three, and for a Type II report they want it dated across the observation period. Parameter's agents test every release and produce a report from each run, so that evidence is always current.

[ FAQ ]

Frequently asked questionsabout SOC 2 penetration testing

Start testing today.

A URL and credentials is all it takes.

First findings land within 24 hours.