Cloud Sentry
Compliance

You inherit 50+ controls the day we operate your environment.

When someone else operates your environment, a large share of your control obligations move onto their side of the line, and this page maps which ones.

Checking a control is not operating it.

Compliance automation platforms are good at one thing: confirming that a configuration matches a rule. That is useful, and it is not the work. Someone still has to operate the control, and fix what the check finds.

When we operate your environment, a large share of those obligations are satisfied by work we already run, and the evidence is a by-product of doing it, not a screenshot of a green checkmark. That is compliance built into operations rather than bolted on top. See how it becomes an audit-ready program, then read the map below to see which control families move onto our side of the line.

What control inheritance means

Three ideas, in the language a buyer or an auditor already uses.

Shared responsibility

Every framework, and every cloud platform, splits obligations between you and whoever operates the layer beneath you. Your cloud provider secures the data center; whoever runs your identity, devices, and tenants owns the controls above it. The more of that we operate, the more of the obligation is ours.

Complementary user entity controls

When a provider hands you a SOC 2 report, it lists complementary user entity controls (CUECs): the things you still have to do for the provider's controls to hold. Normally that list is yours to run. When we operate your environment, we run much of it for you, and we make the split explicit so your auditor is not left guessing.

Evidence from operation

Proof that comes from running the control, not a picture of a passing check. Change records, access reviews, ticket history, and logs are by-products of the work we already do. That is the kind of evidence that survives an enterprise vendor security review.

The control map

See which SOC 2 controls move onto our side of the line when we operate your environment, and where the responsibility stays with you.

We operate

We run this control as part of operating your environment; the evidence is a by-product of the work.

Shared

We operate our portion and document the rest, which stays with your team or your cloud providers.

Yours

This stays with your leadership or your business processes; we support it, but we do not own it.

Ownership reflects how we typically operate; your exact split is confirmed during scoping.

SOC 2

All 51 Trust Services Criteria across the five categories (AICPA), grouped by domain.

SOC 2 readiness
16 We operate22 Shared13 Yours

38 of the 51 criteria move onto our side of the line when we operate your environment; the 13 that stay with you are governance and business-process decisions no operator can hold for you.

Tags reflect how we typically operate when we run your identity, endpoints, cloud, logging and detection, backups, change management, and vendor register. Domains that stay entirely with you are collapsed; open one to see the detail.

CC1 Control environment

5 Yours
  • CC1.1 Commitment to Integrity and Ethical Values

    Yours

    Your leadership sets the tone, the code of conduct, and the ethical expectations for the business; that ownership stays with you.

  • CC1.2 Board Independence and Oversight

    Yours

    Board or ownership oversight of your control environment is a governance role only you can hold.

  • CC1.3 Organizational Structure and Authorities

    Yours

    How you structure roles, authority, and reporting lines is a decision for your leadership.

  • CC1.4 Commitment to Competent Personnel

    Yours

    Hiring, evaluating, and developing your people stays with you; once roles are defined, we operate the access that follows.

  • CC1.5 Accountability for Internal Controls

    Yours

    Holding individuals accountable for their control responsibilities is a management function you retain.

CC2 Communication and information

3 Shared
  • CC2.1 Use of Relevant Quality Information

    Shared

    We supply operational data, logs, and reporting from the systems we run; deciding what information your objectives need stays shared.

  • CC2.2 Internal Communication of Information

    Shared

    We document and communicate the controls we operate to your team; communicating your own policies internally stays with you.

  • CC2.3 External Communication

    Shared

    We produce the operational evidence external parties ask for; what you tell customers and regulators is yours to own.

CC3 Risk assessment

2 Shared2 Yours
  • CC3.1 Specification of Objectives

    Yours

    Setting your business and compliance objectives is a leadership decision that frames everything beneath it.

  • CC3.2 Risk Identification and Analysis

    Shared

    We identify and track technical and operational risk in the environment we run; business and strategic risk you weigh together with us.

  • CC3.3 Fraud Risk Consideration

    Yours

    Assessing fraud risk across your business processes stays with your leadership and finance functions.

  • CC3.4 Impact of Changes on Internal Control

    Shared

    We assess how infrastructure and tooling changes affect controls; organizational and business-model changes you assess with us.

CC4 Monitoring activities

2 Shared
  • CC4.1 Ongoing and Separate Evaluations

    Shared

    We run continuous monitoring and produce evidence from the systems we operate; independent oversight of the program stays with you.

    Replaces a compliance-automation platform's evidence collector.

  • CC4.2 Communication of Deficiencies

    Shared

    We surface and route the deficiencies our monitoring finds; how they are escalated and remediated across the business stays shared.

CC5 Control activities

1 We operate2 Shared
  • CC5.1 Control Activity Selection and Development

    Shared

    We design and run the technical controls in scope; selecting controls for risks outside the environment we operate stays shared.

  • CC5.2 General Technology Controls

    We operate

    We operate the general technology controls behind your systems: access, change, and operations management across the platforms we run.

  • CC5.3 Policies and Procedures

    Shared

    We provide and version the policies for the operations we run; adopting and enforcing them across your organization stays shared.

    Replaces a policy-template subscription.

CC6 Logical and physical access

7 We operate1 Shared
  • CC6.1 Logical Access Security

    We operate

    We operate identity, single sign-on, and multi-factor enforcement across the tenants and systems we manage.

    Replaces a standalone SSO/MFA product.

  • CC6.2 User Registration and Authorization

    We operate

    We run joiner and mover provisioning so access is granted only through an authorized, documented request.

    Replaces a separate identity-governance tool.

  • CC6.3 Role-Based Access Management

    We operate

    We operate role-based access and least-privilege reviews across the systems we manage.

  • CC6.4 Physical Access Restrictions

    Shared

    Device-level access controls we operate; data-center and facility access inherits from your cloud providers.

  • CC6.5 Asset Decommissioning Protections

    We operate

    We handle secure deprovisioning and data removal when devices and accounts are retired.

  • CC6.6 External Threat Protection

    We operate

    We operate the boundary protections, DNS and edge security, and hardening that keep external threats out.

  • CC6.7 Data Transmission Controls

    We operate

    We enforce encryption in transit and controlled transfer across the systems we manage.

  • CC6.8 Malicious Software Prevention

    We operate

    We run managed endpoint detection and response and malware prevention on the devices we manage, on the endpoint tooling already in your Microsoft 365 licensing.

CC7 System operations

5 We operate
  • CC7.1 Vulnerability Detection and Monitoring

    We operate

    We run vulnerability detection and configuration monitoring across the environment we operate.

    Replaces a standalone vulnerability scanner.

  • CC7.2 Anomaly Monitoring

    We operate

    We centralize logging and monitor for anomalies through managed detection on the systems we run.

    Replaces a separate SIEM or log-retention service.

  • CC7.3 Security Event Evaluation

    We operate

    We triage and evaluate security events to separate a real incident from noise.

  • CC7.4 Incident Response Program

    We operate

    We run the incident-response program: detection, containment, and coordinated response for the environment we operate.

    Replaces a separate incident-response retainer.

  • CC7.5 Incident Recovery

    We operate

    We restore service and data through the recovery processes we operate after an incident.

CC8 Change management

1 We operate
  • CC8.1 Change Authorization and Implementation

    We operate

    We operate authorized, tracked change management for the systems we run, with the change record itself as evidence.

    Replaces a separate change-management tool.

CC9 Risk mitigation

2 Shared
  • CC9.1 Business Disruption Risk Mitigation

    Shared

    We operate the backup, recovery, and continuity controls for the environment we run; continuity planning across the business stays shared.

  • CC9.2 Vendor and Partner Risk Management

    Shared

    We maintain the vendor register and review the technology suppliers we manage; risk decisions on your own vendors stay shared.

    Replaces a standalone vendor-risk (TPRM) tool.

A1 Availability

2 We operate1 Shared
  • A1.1 Processing Capacity Management

    Shared

    We monitor and manage capacity for the infrastructure we operate; forecasting demand for your own applications stays shared.

  • A1.2 Environmental and Backup Protections

    We operate

    We operate backup, environmental monitoring, and recovery protections for the systems we manage.

    Replaces a standalone backup/DR service.

  • A1.3 Recovery Plan Testing

    We operate

    We run and document recovery testing for the environment we operate, so the plan is proven rather than assumed.

C1 Confidentiality

2 Shared
  • C1.1 Confidential Information Identification

    Shared

    We enforce handling and access controls for confidential data on the systems we run; classifying what counts as confidential stays with you.

  • C1.2 Confidential Information Disposal

    Shared

    We operate secure disposal on the media and systems we manage; disposal in systems outside our scope stays shared.

PI1 Processing integrity

5 Shared
  • PI1.1 Processing Information Quality

    Shared

    We operate the controls around the platforms that carry your data; the correctness of your application logic stays with your product team.

  • PI1.2 System Input Controls

    Shared

    We secure and monitor the systems that receive input; validating your business inputs stays with your team.

  • PI1.3 System Processing Controls

    Shared

    We operate infrastructure and access controls around processing; the accuracy of your processing logic stays yours.

  • PI1.4 System Output Controls

    Shared

    We control access to and delivery of system output; verifying output against your business rules stays shared.

  • PI1.5 Storage Controls

    Shared

    We operate storage access, encryption, and backup on the systems we manage; data-model correctness stays with your team.

P1 Privacy

2 Shared6 Yours
  • P1.1 Privacy Notice

    Yours

    Your privacy notice, and how you describe your data practices, is yours to author and publish.

  • P1.2 Choice and Consent

    Yours

    Collecting and honoring consent choices is a business-process decision you own.

  • P1.3 Collection of Personal Information

    Yours

    What personal information you collect, and why, is a decision for your business.

  • P1.4 Use of Personal Information

    Yours

    Using personal information in line with your stated purposes stays with your team.

  • P1.5 Retention of Personal Information

    Yours

    Setting retention periods and disposal timelines for personal information is a policy decision your business owns.

  • P1.6 Data Subject Access

    Shared

    We help fulfill access and deletion requests on the systems we operate; verifying identity and approving each request stays with your team.

  • P1.7 Third-Party Disclosure

    Yours

    Deciding which third parties receive personal information, and under what terms, is a business decision you own.

  • P1.8 Breach Notification

    Shared

    We detect, contain, and provide the forensic record when an incident touches personal data; the notification decision and communications stay with your team and counsel.

The 51 items in the SOC 2 view are the Trust Services Criteria themselves, the public structure every report maps to. The specific controls you implement against them, and the exact ownership split, are finalized against your scope during onboarding.

Sources: AICPA Trust Services Criteria (SOC 2). This is a public framework structure; the specific controls in your report are unique to your organization, and nothing here represents a Cloud Sentry certification.

A failing check comes with the person who fixes it.

A tool can tell you a control has drifted. It cannot operate the control, and it cannot close the gap; that work still lands on someone. Reviewers are also getting sharper about evidence that was assembled to pass a check rather than produced by doing the work.

Because our evidence is a by-product of operating your environment, it holds up. And a failing check is not a notification you are left to chase; it comes with an accountable operator whose job is to fix it.

A compliance platform

Flags the gap on a dashboard. Closing it is left to you.

An audit-mill report

Looks clean the day it ships, then ages badly under enterprise vendor review.

Cloud Sentry

Evidence is generated by operating the control, and every failing check routes to a named operator who fixes it.

Proof on demand

The evidence, ready when the reviewer asks.

The controls we operate generate their own proof, and it lives in the platform. When a buyer or an auditor asks, you share a scoped, time-bounded view through the Evidence Vault: no account for them to create, and every view logged.

See where the line falls for you.

Read the published plan structure, or walk the whole operated partnership.

Published structure with a written annual escalator cap, and an entry rung you can start today. Read what each tier covers before anyone calls you.

The whole function run end to end, with the controls, the evidence, and one accountable lead who answers for the outcome.