Drinking Our Own Champagne: How We Completed Our SOC 2 Using Locktivity & Evidence Packs
Locktivity
Continuous Compliance
When you build software designed to streamline compliance, there is only one true test of your philosophy: using your own system to pass your own audit. As of August 15, we officially received our SOC 2 report. Rather than relying on legacy GRC portals, piles of static screenshots, or endless live screen-shares, we ran our entire audit end-to-end using Locktivity and open-source Evidence Packs. “The big legacy GRC platforms are amazing for auditors... until you realize they are a complete black box and you end up needing to re-validate evidence. The fact that the epack evidence was open source, and each artifact signed and traceable, made it incredibly easy to validate the source of the evidence.” said Beau Butaud of Render Compliance.
How We Completed SOC 2 with Automated Evidence | Locktivity
We completed our SOC 2 audit on Locktivity: 75% of evidence collected automatically, signed Evidence Packs, and no "log in and show me" auditor calls.
Drinking Our Own Champagne: How We Completed Our SOC 2 Using Locktivity & Evidence Packs
When you build software designed to streamline compliance, there is only one true test of your philosophy: using your own system to pass your own audit.
As of August 15, we officially received our SOC 2 report.
Rather than relying on legacy GRC portals, piles of static screenshots, or endless live screen-shares, we ran our entire audit end-to-end using Locktivity and open-source Evidence Packs. Over 75% of our audit evidence was collected and monitored automatically on a daily basis, allowing our auditor to verify controls directly down to the source of truth without requiring us to log in and show it live.
More than just a milestone, this audit proved something fundamental: we are witnessing a shift to GRC for the AI Era. When AI has access to cryptographically verifiable data and rich, native context, compliance evolves from AI for speed (hallucinating drafts and rushing low-quality prep) to AI for quality at speed.
Here is a look at how we leveraged our platform features to power our SOC 2 compliance - and why this developer-native, context-rich approach changes the auditing game.
The Locktivity Engine: Automated Collection at the Source
To prepare for our audit, we didn't spin up heavy administrative overhead or pull engineers off core product development. We let Locktivity do the heavy lifting:
Continuous Daily Pipelines: Around 75% of our total evidence was automatically gathered and checked every single day, keeping our posture audit-ready in real time. Collectors pull from the systems that enforce our controls. From cloud providers, identity providers, MDMs, CI/CD tools and the Locktivity document repository- continuously syncing policies and documentation from our actual sources of truth (for us, Github and Google Drive).
Automated Access Reviews via MCP: We streamlined our access reviews using the Model Context Protocol (MCP), removing the traditional friction of manually cross-referencing user lists across disparate platforms. Collectors run at the internal level collect human and non-human users from our critical systems such as production environment, CI/CD tools, email system, and IdP, including permissions, last logins and MFA settings. Within minutes we have a full picture of who has access to do what, how the login is secured and where supported, whether that user is active.
Because our evidence was continuously compiled into open-source Evidence Packs (epack.dev), every collected artifact was cryptographically verifiable, signed, and structured straight from our live infrastructure.
GRC for the AI Era: Moving from Speed to Quality at Speed
First-generation GRC tools used AI primarily for speed - generating generic policy text, summarizing questionnaires, or speeding up answering questionnaires. But speed without context and trustworthy data just produces junk faster.
Locktivity represents a fundamental shift: GRC for the AI Era.
When AI agents and automation operate on top of verifiable, source-level data, the dynamic changes completely:
Verifiable Truth, Not Hallucinations: AI workflows don't guess or extrapolate from outdated dashboards. They query real-time git commits, active AWS configurations, and signed Evidence Packs.
Rich Native Context: By linking policies (Google Drive/GitHub) directly to operational state, AI and automation understand the why behind a control, enabling intelligent change monitoring and context-aware access reviews.
Quality at Speed: You don't have to choose between moving fast and maintaining high-quality security controls. Grounded context gives leadership, engineers, and auditors absolute confidence in the accuracy of the underlying data.
“The big legacy GRC platforms are amazing for auditors... until you realize they are a complete black box and you end up needing to re-validate evidence.
The fact that the epack evidence was open source, and each artifact signed and traceable, made it incredibly easy to validate the source of the evidence.” Beau Butaud of Render Compliance.
The Auditor Experience: No More "Log In and Show Me" Walkthroughs
One of the most exhausting parts of a traditional audit is the "prove it" phase. Even after receiving screenshots or vendor reports, auditors usually require engineers to hop on a call, log into AWS, GitHub, or identity providers, and click around live to prove controls are active.
“Having it served up through the Locktivity pipeline and UI made any audit back-and-forth handled smoothly and in context.
The Locktivity MCP allowed our in-house AI tooling to perform testing procedures with access to audit evidence and project context.” Butaud noted the ease of the process, while looking forward to pending enhancements, “it's only up from here. I can see the following year’s audit clicking with configurable audit profiles and year-over-year diff management on collector versions.”
Because Locktivity packages raw, native data, our auditor could audit straight down to the source without needing us to log in and demonstrate it:
Direct Source Verification: The auditor inspected raw git histories, cloud configurations, and synced documents in their true native context.
Direct Evidence Pinning: When the auditor had a specific question, they didn't need a screen-share call - they simply pinned questions directly to specific pieces of evidence (down to a line of code, a commit, or a configuration state).
Zero Verification Friction: Because the data was tamper-evident, signed, and directly linked to source systems, the auditor had complete trust in the evidence.
"When an auditor can audit directly at the source and pin questions to specific lines of evidence, you eliminate 90% of the usual back-and-forth ambiguity - and kill off the dreaded 'log in and show me' live calls." - Rachel Curran, co-founder at Locktivity.
The Impact: High-Quality Compliance Without the Drag
By dogfooding Locktivity, we re-validated the key benefits our clients experience:
75% Automation: Daily pipelines eliminated manual audit prep, screenshot hoarding, and spreadsheet tracking.
AI-Era Precision: Verifiable data enabled high-precision automation (like MCP access reviews) without sacrificing context.
No Drain on Engineering Time: Auditors verified source data independently, saving hours of engineer time.
Pinpoint Collaboration: Pinning questions directly to evidence artifacts meant zero time spent deciphering what the auditor was referring to.
Total Audit Integrity: Source-level, verifiable evidence gave our auditor absolute confidence while keeping our engineering team focused on building product.
Practice What You Preach
Achieving our SOC 2 report as of August 15 wasn't just a compliance milestone - it was proof of concept. When evidence is open, transparent, and automatically synced from your true systems of record, compliance shifts from a disruptive annual sprint into an automated, everyday habit. An Evidence Pack (epack.dev) is portable and verifiable from anywhere. Signed using SigStore, pinned to open source collectors, any auditor or customer can verify an epack.
Curious to see how Locktivity, Evidence Packs, and GRC for the AI Era can transform your next audit?
Explore the platform at locktivity.com.
Check out our open-source evidence specifications at evidencepack.org and epack.dev.