Built to support your
SOC 2 controls, honestly labeled.
Dwayo isn't SOC 2 certified ourselves — that's an audit of our own organization we haven't pursued yet, and we won't pretend otherwise. What we build are systems engineered so your SOC 2 controls hold up, with the evidence your auditor will actually ask to see.
Your audit,
our architecture.
SOC 2 is an audit of your organization's controls across the Trust Service Criteria — security, availability, confidentiality, processing integrity, and privacy. We don't hold that certification ourselves, but the systems we build map directly to those criteria, so when your auditor asks "how does this AI system fit our controls," there's a real answer.
See our full Trust & Safety framework for the underlying architecture — this page maps it specifically to SOC 2's criteria.
Trust Service Criteria,
mapped to what we build.
The same architecture decisions we make on every project, mapped to SOC 2's five Trust Service Criteria.
| Trust Service Criterion | What we build |
|---|---|
| Security | Role-based access control with a full audit trail, encryption at rest (AES-256) and in transit (TLS 1.3), input/output guardrail layers. |
| Availability | Production monitoring with drift detection, operational runbooks for deploy/rollback, and model-agnostic architecture so a provider outage doesn't take the whole system down. |
| Confidentiality | PII redaction pipelines before any data reaches a model, zero-data-retention agreements with model providers, VPC/on-premise deployment options. |
| Processing Integrity | Automated eval suites on every deployment, output schema enforcement, confidence scoring with fallback paths. |
| Privacy | Configurable data residency and retention/deletion pipelines, a DPA available with UK/EU-specific terms on request. |
Evidence,
not just architecture.
Controls only help with an audit if they produce something your auditor can actually review.
Every access, every model call, logged and queryable — not just captured somewhere, but retrievable when an auditor asks.
The Trust Spec delivered on every engagement, with controls mapped explicitly to the criteria your auditor will test against.
Including UK/EU-specific terms — see our vendor security page for how to request it.
No sales pitch,
just how we work.
Four things that are true of every engagement, not just this one.
Built inside your existing stack — not a rewrite, and not a 7-month hiring cycle.
You know the number before you sign. No open-ended retainer.
Security, data handling, and compliance commitments on paper — not a verbal promise.
You own the code and the model config at project completion. We don't hold it hostage.
Before you
book a call.
The questions we get asked most about SOC 2 and AI — answered straight, no sales pitch.
Is Dwayo SOC 2 certified?
Not yet — SOC 2 is an organizational audit of Dwayo itself that we haven't pursued, and we won't claim otherwise. What we build are systems engineered to support your SOC 2 controls and produce the evidence your auditor will ask for, regardless of our own certification status.
Can you help us pass a SOC 2 audit?
Yes — we map the controls we build by default (access logs, encryption, monitoring, change management) to your auditor's specific control list, and produce the artifacts and evidence they'll ask to see.
Do you have a DPA (Data Processing Agreement)?
Yes, including UK/EU-specific terms. Available on request — see our vendor security page or contact us directly.
What's the difference between this and your general Trust & Safety framework?
Same underlying architecture — this page maps it specifically to SOC 2's Trust Service Criteria, for teams that need to show an auditor exactly how an AI system fits their existing control framework.
Tell us what
your auditor is asking for.
Book a 30-minute call — we'll map our controls to your specific audit requirements before you commit to anything.