Built for H0: Hack the Zero Stack · AWS + Vercel

SOC 2 compliance, automated
by AI

Connect your GitHub, and ZeroAudit's AI agent automatically collects evidence across 42 SOC 2 Type II controls — turning months of manual work into a 2-minute scan.

See how it works
$30,000
Average audit cost saved
42
SOC 2 controls monitored
2 min
Evidence collection time
2
Compliance frameworks

No credit card required · SOC 2 Type II certified infrastructure · Powered by AWS DynamoDB

How it works

From zero to audit-ready in three steps

🔌STEP 01

Connect your tools

OAuth connect GitHub in one click. PagerDuty and AWS CloudTrail integrations read your real operational data.

🤖STEP 02

AI agent scans everything

Our agent analyzes pull requests, Dependabot alerts, branch protection, incident history, and IAM logs against 42 SOC 2 controls.

📄STEP 03

Get audit-ready reports

Download SOC 2 Type II and ISO 27001 compliance reports in seconds. Share directly with your auditor.

Everything you need for SOC 2

🔍
Real Evidence Collection

Reads actual PRs, Dependabot alerts, branch protection rules, and CloudTrail logs — not simulated data.

🧠
AI Classification

Grok AI analyzes each artifact against SOC 2 Trust Service Criteria and generates reasoning for auditors.

📊
Evidence Map

Visual dashboard showing covered, partial, and missing controls across all 42 SOC 2 requirements.

📋
SOC 2 Type II Report

Generate audit-ready PDF reports with executive summary, control evidence, and remediation recommendations.

🔄
ISO 27001 Crosswalk

Automatically maps SOC 2 controls to ISO 27001:2022 Annex A requirements.

DynamoDB Single-Table

Built on AWS DynamoDB with single-table design and GSI-optimized access patterns for multi-tenant evidence storage.

Built on the right stack

Designed for the H0 hackathon judges who care about architecture

Data Layer

AWS DynamoDB Single-Table Design

One table, two GSIs, zero joins. Evidence artifacts are stored with ORG#orgId as partition key for tenant isolation. GSI1 enables control-scoped queries, GSI2 enables status-based gap analysis.

PK/SK patternGSI1 — by controlGSI2 — by statusMulti-tenant
AI Layer

Multi-step Agentic Reasoning

The agent fetches real evidence from GitHub, PagerDuty, and AWS CloudTrail, then uses Grok AI to classify each artifact against SOC 2 controls with structured JSON output: coverageStatus, riskLevel, and reasoning.

Grok AIStructured outputsFire-and-forgetDynamoDB state

Ready to automate your SOC 2 audit?

Connect GitHub and run your first compliance scan in under 2 minutes.

No credit card required