[ SOC 2 penetration testing ]
Pentest evidence for SOC 2.From every release.
AI agents that find vulnerabilities in your web apps, APIs, and infrastructure. Continuously, so there is a dated test inside every observation period, not one from the year before.
See first findings in 24 hours
Built by the team that secured:
Built by the team that secured:
[ what SOC 2 asks ]
What the criteria ask,and what a run gives you.
SOC 2 never says penetration test. Auditors ask for one anyway, because it is the cleanest evidence for these criteria.
5 covered by every run · 1 shared with your assessor
CC7.1 · Identify vulnerabilities
Procedures to identify new vulnerabilities and evaluate the system's susceptibility to them. A test on every release, with a report from each run, makes the process visibly continuous.
covered by every run
Evidence to keep: dated report per release
CC4.1 · Evaluate independently
Ongoing and separate evaluations of whether controls are present and functioning. A third-party test is stronger evidence than an internal one, and the agents sit outside your team, proving each finding with a working exploit.
covered by every run
Evidence to keep: the report, plus who ran it
CC7.4 and CC7.5 · Respond and recover
Identified vulnerabilities and incidents responded to and resolved. Each finding carries its proof, a fix, and a re-test on that fix, in the same report.
covered by every run
Evidence to keep: finding, fix, re-test, dates
Type II observation window
For Type I the test can fall any time in the 12 months before the report date. For Type II it has to happen during the audit period. Dated reports from every release cover both.
covered by every run
Evidence to keep: report dates inside the window
CC7.2 · Monitor for vulnerabilities
System components monitored for anomalies that indicate vulnerabilities or new threats. Continuous testing is monitoring made concrete: a run per release, with what it found.
covered by every run
Evidence to keep: the run history
The opinion itself
Whether your controls meet the criteria is the auditor's judgement. Parameter supplies the testing evidence; the service auditor issues the report.
shared with your assessor
Evidence to keep: none; this is the auditor's
[ how it works ]
Connect
A repository, a URL with test accounts, or a read-only cloud role. Testing starts within hours. No scoping call, no engagement to book.
Test every release
Agents test the running app, the code behind it, the cloud it runs on, and the packages it depends on, as different users, every time you ship. Every finding is exploited before it is reported.
Hand over the run
Each run produces a report with scope, method, findings, proof, and remediation status. Re-tests happen on fix, so the evidence is never older than the last release.
[ definition ]
Does SOC 2 require a penetration test?
Not by name. SOC 2's Trust Services Criteria ask you to identify vulnerabilities (CC7.1), evaluate your controls independently (CC4.1), and act on what you find (CC7.4). A penetration test is the evidence auditors expect for all three, and for a Type II report they want it dated across the observation period. Parameter's agents test every release and produce a report from each run, so that evidence is always current.
[ FAQ ]
Frequently asked questionsabout SOC 2 penetration testing
[ explore ]
Keep reading.The platform, and other frameworks.
AI penetration testing
How the agents work, what they cover, reports, and pricing.
Read more
ISO 27001 penetration testing
What ISO 27001 controls expect from penetration testing, clause by clause, and how continuous runs supply the evidence.
Read more
PCI pentest
What PCI DSS v4.0 Requirement 11.4 asks, what a QSA wants, and where continuous testing fits alongside the annual test.
Read more
FedRAMP penetration testing
What FedRAMP requires of penetration testing, the 3PAO's role, and how continuous testing supports continuous monitoring.
Read more
Not sure which fits?
Tell us what you are shipping and we will scope the test in minutes.
Book a call
Start testing today.
A URL and credentials is all it takes.
First findings land within 24 hours.
















