Connexion sécurisée en cours…
Nous préparons votre essai Apsolu Pro. Vous pouvez revenir à l’accueil à tout moment.
Nous préparons votre essai Apsolu Pro. Vous pouvez revenir à l’accueil à tout moment.
Last updated: May 19, 2026 — Internal & enterprise-facing — Estimated effort: 5–8 j/h internal + external budget
SOC 2 Type II certification is the de-facto trust credential for B2B SaaS sold to mid-market and enterprise clients. For APSOLU Pro, achieving it unlocks procurement approval from large hotel groups, AMO firms, and real-estate developers that mandate it as a vendor requirement. This document covers the gap analysis against all nine Common Criteria (CC1–CC9), a phased 6–12 month plan to reach the audit observation period, auditor selection guidance, and a realistic budget.
Several controls are already implemented or inherited from certified sub-processors. These reduce the gap significantly and should be documented formally before the observation period begins.
Authentication, session management, MFA, and user lifecycle managed by Clerk (clerk.com). Their SOC 2 Type II report covers access control, authentication logging, and credential management.
PostgreSQL database hosted in Frankfurt (EU). Supabase holds a SOC 2 Type II report covering availability, confidentiality, and data encryption at rest (AES-256). Daily backups with 30-day retention.
Application hosting on Vercel Edge Network. Immutable deployments, HTTPS enforced, HSTS enabled. Vercel's SOC 2 Type II covers change management, availability, and infrastructure security.
File storage (photos, documents) on Cloudflare R2 EU region. AES-256 at-rest encryption. Cloudflare's SOC 2 Type II covers physical and logical access to storage infrastructure.
All queries scoped by orgId from Clerk JWT. getOrgIdOrThrow() guards every API route. Cross-org data access is structurally impossible — no path exists in the application code.
5 project roles (OWNER → VIEWER) + Clerk org roles (admin/member). Documented at /trust/permissions. Enforced at the API layer on every request.
TLS 1.3 enforced. HSTS active via Vercel. Content-Security-Policy configured. Rate limiting: 100 req/min (API), 20 req/min (AI routes) at Edge middleware.
Timestamps on all records. SHA-256 checksums on uploaded files. EXIF metadata preserved for photos. Full audit_log table exists for mutations — needs formal retention policy.
Data Processing Agreement published at /legal/dpa. Data residency in EU (Frankfurt). Right to erasure implemented. Sub-processor list maintained.
The SOC 2 Security category comprises nine Common Criteria (CC1–CC9). The table below maps each criterion to APSOLU Pro’s current state, identifies gaps, and assigns a traffic-light status.
| Criterion | Description | Current state | Gaps to close | Status |
|---|---|---|---|---|
| CC1 | Control Environment — governance, ethics, accountability | No formal InfoSec policy or organizational security charter. | Draft and approve: InfoSec Policy, Acceptable Use Policy, Code of Conduct. Designate a security owner (DPO-equivalent). | Gap |
| CC2 | Communication & Information — internal/external comms about security | Security@ email exists. /trust/* pages document controls publicly. | Internal security awareness training (annual, documented). Security incident reporting process communicated to all team members. | Partial |
| CC3 | Risk Assessment — formal risk identification and management | No formal risk register or risk assessment process. | Annual risk assessment exercise. Risk register (threats, likelihood, impact, mitigations). Risk treatment plan. | Gap |
| CC4 | Monitoring Activities — continuous monitoring, internal audit | Vercel deployment logs. Supabase query logs. No SIEM or centralized alerting. | Centralized log aggregation (Axiom / BetterStack / Datadog). Anomaly alerting. Quarterly access reviews. Annual internal audit cadence. | Gap |
| CC5 | Control Activities — policies and procedures for system controls | PR review process exists (GitHub). Lint + build CI gates active. | Formal Change Management Policy. Documented SDLC process. Vendor Management Policy. Documented deployment procedures. | Partial |
| CC6 | Logical & Physical Access — authentication, authorization, network | Clerk auth (SOC 2 Type II). RBAC documented. TLS 1.3. Rate limiting. orgId isolation. | MFA enforcement for all admin/privileged accounts (not just optional). Formal access provisioning/deprovisioning procedure. Quarterly user access review documented. | Partial |
| CC7 | System Operations — monitoring, incident detection and response | Vercel/Supabase platform alerting. No formal incident response plan. | Incident Response Policy (definition, roles, SLAs). Tabletop exercise (annual). Post-incident review process. Documented security incident log. | Gap |
| CC8 | Change Management — SDLC, code review, deployment controls | Git workflow documented (CLAUDE.md). PR + review process. Husky pre-push hooks (lint + tsc). Immutable Vercel deployments. | Formal Change Management Policy referencing the existing process. Emergency/hotfix change classification (HF-xxx circuit exists — document formally). Rollback procedure documented. | Partial |
| CC9 | Risk Mitigation — vendor mgmt, business continuity, insurance | Sub-processors documented in DPA. Supabase 30-day backups. | Formal Vendor Management Policy + periodic assessments of Clerk/Supabase/Vercel/Cloudflare/OpenRouter. BCP/DR plan with defined RTO/RPO. Annual DR test. Cyber insurance evaluation. | Gap |
The plan is structured in four phases. Phases 1–3 close the gaps identified above. Phase 4 is the formal 6-month audit observation period (no control changes during this window — only evidence collection).
SOC 2 audits must be conducted by a licensed CPA firm. The choice affects cost, turnaround time, and the credibility of the report with prospects. Three tiers are relevant for APSOLU Pro at its current stage:
A-LIGN, Schellman, Prescient Security, Coalfire
Grant Thornton, BDO, RSM, Mazars
Deloitte, PwC, KPMG, Ernst & Young
Manual evidence collection for SOC 2 is extremely time-consuming. Compliance automation platforms reduce the internal effort by 60–70% by pulling evidence automatically from integrations.
Market leader for startup/scale-up SOC 2 automation. Integrates with GitHub, Vercel, Clerk, Supabase, Cloudflare. Automated evidence collection, audit-ready dashboard. Startup program available.
Strong competitor to Vanta. Excellent UI and evidence workflow. Similar integrations. Slightly more expensive at early stage but stronger for multi-framework (SOC 2 + ISO 27001 + GDPR).
Cost-effective alternative. Good for companies at seed/early stage. Fewer integrations than Vanta/Drata but solid for the core SOC 2 workflow.
All figures are estimates for a cloud-native SaaS at APSOLU Pro’s current maturity level. Prices are in USD, excluding VAT.
| Item | Who | Low estimate | High estimate | Notes |
|---|---|---|---|---|
| Compliance automation platform (Year 1) | External — SaaS | $10,000 | $18,000 | Vanta recommended. Startup discount may apply. |
| External penetration test | External — security firm | $8,000 | $15,000 | Web app + API scope. Annual cadence required. |
| SOC 2 Type II audit fee | External — CPA firm | $18,000 | $35,000 | Specialist SaaS firm (A-LIGN / Schellman). Fixed fee. |
| Policy writing (if outsourced) | External — consultant or legal | $3,000 | $8,000 | Can be done internally (saves cost). Templates exist. |
| Security awareness training platform | External — SaaS | $500 | $2,000 | KnowBe4, Curricula, or free Teachable alternative. |
| Log aggregation / SIEM | External — SaaS | $1,200 | $4,800 | Axiom ($100/mo), BetterStack, or Datadog (higher end). |
| Cyber insurance (recommended) | External — insurer | $2,000 | $5,000 | Annual premium. Not strictly required for SOC 2 but expected by enterprise buyers. |
| Total external budget (Year 1) | $43,000 | $85,000 | Recurring ~50% from Y2 (audit renewal + platform) | |
Several high-impact actions require zero external budget and move the needle immediately on the gap analysis:
In Clerk Dashboard → Organization Settings → require MFA for org:admin role. Closes CC6 gap immediately.
Settings → Code Security → Dependabot alerts + security updates. Automated vulnerability detection — required for CC7.
Add GitHub Actions workflow with CodeQL analysis on every PR. Satisfies SAST requirement for CC5/CC8.
The HF-xxx process in CLAUDE.md is excellent but informal. Extract it into a Change Management Policy document. Closes CC8 gap with almost zero effort.
Designate Christophe (or a co-founder / CTO) as Security Owner in writing. Required for CC1 — no hire needed, just a formal designation.
Configure Supabase log drain + Vercel log drain → Axiom or BetterStack. Centralized audit trail for CC4 — critical for Type II evidence collection.
Questions about this roadmap or our security posture? security@apsolu.app
Permissions & RBAC | Transparence & Audit Trail | DPA (GDPR) | APSOLU Pro