SOC 2 Trust Services Criteria: Pipelock Mapping

Pipelock maps runtime controls and evidence to five SOC 2 Trust Services Criteria without making an audit or attestation claim.

Ready to protect your own setup?

Pipelock maps runtime controls and evidence to five SOC 2 Trust Services Criteria. The mapping does not claim that PipeLab or Pipelock is SOC 2 audited, attested, or certified.

Pipelock supplies product evidence for controls that operate at its boundary. An organization and its auditor decide whether that evidence supports a control test.

Criteria mapping

IDCriterionStatusPipelock mappingLimit
SECSecurityCoveredProxy enforcement, MCP scanning, DLP, and structured audit logs support security controls.
AVAAvailabilityPartialMetrics and health endpoints aid availability monitoring.Capacity planning and service-level agreements remain deployment-specific.
PIProcessing IntegrityCoveredRecorded evidence and verification flows preserve processing integrity.
CONFConfidentialityCoveredDLP and redaction controls protect confidential information in transit and at rest.
PRIVPrivacyPartialPolicy testing helps identify privacy gaps.Data-subject workflows and retention policy remain outside the proxy.

What the mapping means

A covered row identifies the Pipelock controls and evidence that map to that criterion. A partial row identifies the same contribution and its stated limit. The mapping is not an audit result, an attestation, or a certification claim.

Pipelock does not own deployment capacity planning, service-level agreements, data-subject workflows, or retention policy. Those controls belong to the organization operating the deployment.

Use the mapping as evidence

Pipelock’s compliance catalog feeds the assessment output and framework summaries. The SOC 2 mapping gives a reviewer specific product evidence to evaluate. It does not replace the independent auditor who performs an attestation engagement.

Read Compliance Evidence Substrate for the boundary between product evidence and audit status.

Further reading

Frequently asked questions

Is Pipelock SOC 2 certified or audited?
No. Mapping Pipelock findings to SOC 2 Trust Services Criteria does not make PipeLab or Pipelock SOC 2 audited, attested, or certified. Pipelock supplies runtime evidence that an auditor can evaluate inside an organization’s program.
Which SOC 2 criteria does Pipelock map?
Pipelock maps Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security, Processing Integrity, and Confidentiality are marked covered. Availability and Privacy are marked partial.
What does Pipelock not cover for SOC 2?
Capacity planning, service-level agreements, data-subject workflows, and retention policy remain outside the proxy. Those limits appear on the Availability and Privacy rows.

Ready to protect your own setup?

See Assess reports →