Security posture

FinOps SOC 2 — the audit trail is the product.

Tallywyrmis a 24/7 FinOps agent for multi-cloud spend. This page names the frameworks the audit trail already satisfies — SOC 2 Type II, ISO 27001 and FedRAMP Moderate — and how the data-handling decisions we already publish on /privacy back each one for cloud cost compliance.

The short version
Every saving ties to a PR, a deploy, and a post-deploy measurement.
The audit trail exists before the savings do. Same formula on /privacy, /terms and the FAQ; this page just names the frameworks it satisfies.
1 · SOC 2 Type II

The five trust-service criteria, covered end-to-end.

The audit trail we keep on /privacy already spans the weekly cadence your SOC 2 assessor runs against. The list below maps each criterion to the surface that satisfies it.

Trust-service criteria posture
The wording below matches what /terms publishes on the weekly audit pass and what /privacy publishes on the audit trail retention.
Every saving is attributable end-to-end — same audit trail the SOC 2 assessor runs against.
Trust-service criteria coverage
  • Security — read-only credentials via the OIDC trust you already operate, scoped to the accounts you grant.
  • Availability — hourly inventory and weekly audit pass documented in the service description on /terms.
  • Processing integrity — every recommended change is traceable from inventory snapshot to merged PR to post-deploy measurement.
  • Confidentiality — no write surface against billing, IAM, identity, or any control-plane service; same wording on /privacy.
  • Privacy — inventory, audit events, and weekly report metadata covered by the retention windows on /privacy.
2 · ISO 27001

Annex A controls, risk treatment and the SOA.

Supplier-relationship controls are the ones buyers ask about first — the credentials are issued by you, brokered through your existing OIDC trust, not collected from the agent.

Annex A coverage
The supplier-relationship controls (A.15) bound the read-only credential contract; the rest of Annex A flows from the SOC 2 and FedRAMP posture on this page.
  • A.5–A.18 control families — risk treatment, statement of applicability, and supplier-relationship controls bound the read-only credential scope.
  • Risk treatment register — published alongside the SOC 2 trust-service-criteria posture this page covers.
  • Supplier-relationship controls (A.15) — the cloud credentials are issued by you, brokered through your OIDC trust, not accepted from the agent.
  • Statement of applicability — every Annex A control is either implemented by the platform or by your tenant on top of it, no exceptions hidden in the appendix.
3 · FedRAMP Moderate

Moderate baseline, continuous monitoring, US-region residency.

The control set your agency already audits against. Mapped through SOC 2 and ISO 27001 above; the cadence below is exactly what established assessors expect to see.

Moderate baseline posture
Hourly inventory plus weekly audit pass is the cadence the audit trail was designed around; US-region data residency is opt-in per workspace, default enabled.
  • Moderate baseline — the control set your agency already audits against, mapped through the SOC 2 + ISO 27001 posture above.
  • Continuous monitoring — hourly inventory + weekly audit pass is exactly the cadence established control assessors expect to see.
  • US-region data residency — inventory, audit events and weekly reports stay in US regions; cross-region replication is opt-in per workspace.
  • NIST 800-53 mapping — implicit through the SOC 2 trust-service-criteria and ISO 27001 Annex A coverage; no separate attestation paper.
4 · Data handling

The credential contract and the audit-trail export, together.

Two surfaces back all three frameworks above: the read-only credential contract already on /privacy, and the weekly audit-trail CSV export finance and security teams reconcile against.

Bring-your-own credential scope
Same wording as /privacy. The credential we ask for is the smallest one that produces a useful saving.
  • Read-only scope against the granted accounts — same wording on /privacy and in the FAQ.
  • Brokered through your existing OIDC trust, never long-lived static keys.
  • No write surface — cannot write to billing APIs, IAM, identity, or any control-plane service.
  • No organisation-admin or account break-glass role, no role escalation, no cross-account assume-role into resources you have not already federated.

Full contract and retention windows on /privacy.

Audit trail
Weekly CSV export of the audit-trail row set.
Available from the dashboard to authenticated users — one row per offender plus a summary header row, ready for Excel or Sheets.
PR diff, deploy timestamp, post-deploy measurement, credit applied — one CSV, one audit window.
  • Each saving ties to a diff, a PR, a deploy timestamp and a post-deploy measurement — the same attribution schema the FAQ describes.
  • Weekly CSV export of the most recent savings report available in the dashboard; one row per offender plus a summary header row, ready for Excel or Sheets.
  • Audit verifications, audit diff and the report week are exported alongside the savings rows so the file is the same evidence pack finance and security teams already reconcile against.
  • The retention window on /privacy is the same that bounds the export — 13 months minimum, configurable per workspace.

Frequently asked format on /faq.

5 · Frameworks we publish against

Same badges as the landing page, /pricing, /privacy, /terms and /faq.

The audit trail we describe above is what these frameworks already demand — nothing on this page is a new attestation, it is a public restatement.

  • SOC 2 Type II
  • ISO 27001
  • FedRAMP Moderate
  • EU CSRD
  • SEC climate disclosure
  • GDPR
See pricingRead the privacy notice →FAQ on the audit trail →Pricing in three percentage-of-savings tiers.