Compliance — SOC 2

Built to support your
SOC 2 controls, honestly labeled.

Dwayo isn't SOC 2 certified ourselves — that's an audit of our own organization we haven't pursued yet, and we won't pretend otherwise. What we build are systems engineered so your SOC 2 controls hold up, with the evidence your auditor will actually ask to see.

What this means

Your audit,
our architecture.

SOC 2 is an audit of your organization's controls across the Trust Service Criteria — security, availability, confidentiality, processing integrity, and privacy. We don't hold that certification ourselves, but the systems we build map directly to those criteria, so when your auditor asks "how does this AI system fit our controls," there's a real answer.

See our full Trust & Safety framework for the underlying architecture — this page maps it specifically to SOC 2's criteria.

Control mapping

Trust Service Criteria,
mapped to what we build.

The same architecture decisions we make on every project, mapped to SOC 2's five Trust Service Criteria.

Trust Service CriterionWhat we build
SecurityRole-based access control with a full audit trail, encryption at rest (AES-256) and in transit (TLS 1.3), input/output guardrail layers.
AvailabilityProduction monitoring with drift detection, operational runbooks for deploy/rollback, and model-agnostic architecture so a provider outage doesn't take the whole system down.
ConfidentialityPII redaction pipelines before any data reaches a model, zero-data-retention agreements with model providers, VPC/on-premise deployment options.
Processing IntegrityAutomated eval suites on every deployment, output schema enforcement, confidence scoring with fallback paths.
PrivacyConfigurable data residency and retention/deletion pipelines, a DPA available with UK/EU-specific terms on request.
What you get

Evidence,
not just architecture.

Controls only help with an audit if they produce something your auditor can actually review.

01Audit-ready logs

Every access, every model call, logged and queryable — not just captured somewhere, but retrievable when an auditor asks.

02Documented controls

The Trust Spec delivered on every engagement, with controls mapped explicitly to the criteria your auditor will test against.

03A DPA on request

Including UK/EU-specific terms — see our vendor security page for how to request it.

Why Dwayo

No sales pitch,
just how we work.

Four things that are true of every engagement, not just this one.

~6 weeks to first production feature

Built inside your existing stack — not a rewrite, and not a 7-month hiring cycle.

Priced by milestone, not by the hour

You know the number before you sign. No open-ended retainer.

Written Trust Spec before any code

Security, data handling, and compliance commitments on paper — not a verbal promise.

Full IP transfer, no lock-in

You own the code and the model config at project completion. We don't hold it hostage.

Common questions

Before you
book a call.

The questions we get asked most about SOC 2 and AI — answered straight, no sales pitch.

Is Dwayo SOC 2 certified?

Not yet — SOC 2 is an organizational audit of Dwayo itself that we haven't pursued, and we won't claim otherwise. What we build are systems engineered to support your SOC 2 controls and produce the evidence your auditor will ask for, regardless of our own certification status.

Can you help us pass a SOC 2 audit?

Yes — we map the controls we build by default (access logs, encryption, monitoring, change management) to your auditor's specific control list, and produce the artifacts and evidence they'll ask to see.

Do you have a DPA (Data Processing Agreement)?

Yes, including UK/EU-specific terms. Available on request — see our vendor security page or contact us directly.

What's the difference between this and your general Trust & Safety framework?

Same underlying architecture — this page maps it specifically to SOC 2's Trust Service Criteria, for teams that need to show an auditor exactly how an AI system fits their existing control framework.

Get started

Tell us what
your auditor is asking for.

Book a 30-minute call — we'll map our controls to your specific audit requirements before you commit to anything.

01
Book a call30 minutes, no sales deck — just your stack and what you're trying to build.
02
We scope itA written Trust Spec and a fixed-milestone plan, not an hourly estimate.
03
We buildInside your existing stack — first production feature in about 6 weeks.