Controls built for the audit
Every control in the SOC 2 Type II scope — security, availability, confidentiality — is implemented in the platform, with evidence collection built in. The audit is an observation window, not a remediation project.
A stitched stack has a seam-shaped attack surface: every integration is a credential, every sync is a data copy, every vendor is a separate audit. Interlock replaces that sprawl with one platform, one tenancy model, and one compliance boundary.
Interlock was engineered control-by-control to the frameworks below from the first line of code. Formal certifications are in progress — the platform isn’t waiting for them, and neither is the evidence.
Every control in the SOC 2 Type II scope — security, availability, confidentiality — is implemented in the platform, with evidence collection built in. The audit is an observation window, not a remediation project.
The platform is built to the HITRUST CSF r2 control set, including time-series audit retention across every product. If your customers are regulated, your OS already speaks their language.
Interlock's architecture — isolation, auditability, and control coverage — is engineered to the FedRAMP High baseline so the platform can serve public-sector workloads as authorization progresses.
Every record in the shared schema carries its tenant, and the database — not application code — enforces the boundary. Cross-tenant access isn’t a bug class we test for; it’s a query the platform cannot express.
A single org, user, and role model spans all eight products: MFA and passkeys, SSO/SCIM at Scale tiers, and permissions the agents obey the same way people do.
Every action a virtual executive takes is attributed, logged, and reversible — the same audit spine as human activity. You can always answer “who did this, and why.”
Data is encrypted in transit and at rest. Payment flows never touch our servers — Stripe's certified checkout and billing portal handle card data end to end.
Each product runs in its own container with its own release cadence. Products share data through the governed Common Data Core — never through ad-hoc APIs or credential sprawl.
Your company's data trains no shared models and feeds no advertising system. The AI works for the tenant it belongs to, and its context ends at your boundary.
Security reviews, questionnaires, and report requests — we turn them around fast.
Contact security