Reports and the audit binder

Readiness reports, the SOC 2 system description, and a one-click export of everything an auditor asks for.

Guides · 1 min read

Reports turn the state of your workspace into something you can hand to somebody else.

Readiness reports

Per framework, a readiness report shows your score, the full control matrix, which evidence covers each control, and who confirmed the mapping. Missing controls are listed explicitly with the gaps that remain — the report is as useful for planning as it is for showing progress.

System description

SOC 2 reports require a system description. RegShield assembles a draft from what it already knows about your workspace — services, infrastructure, vendors, people — which you then edit. It's a starting point that removes the blank page, not a substitute for your own words.

The audit binder

One export produces a zip containing approved policies, the evidence index, the risk register and the supporting registers. It's the package an auditor asks for at the start of fieldwork.

Trust Center

An opt-in public page that shares your posture with prospects — useful when a customer's security review arrives before your audit is finished. You control what it shows and whether it exists at all.

More in Guides

Policies and approvalAdopt from templates or write your own, take a policy through review, and keep a versioned approval record.Access reviews and offboardingFind access that should have been removed, and confirm independently that it actually was.Team and rolesInvite people, what each role can do, and how account activity is recorded.
← All documentation