RepoScope Compliance intelligence for your codebase

SOC 2 Type II — Management Assertion

Date: June 27, 2026
Company: Acme Corp
Audit Period: 2026-01-01 to 2026-12-31

Executive Summary

Acme Corp's codebase was assessed against the AICPA Trust Services Criteria (2017, with 2022 revisions) (SOC 2 Type II Type II) using automated code-level analysis. The assessment covers 13 controls, of which 6 are testable at the code level (46% coverage).

Overall Posture Score: 83/100 — Good

Key Findings

Scope & Limitations

This assessment covers CODE-LEVEL controls only. The following areas require separate, organizational assessment:

Disclaimer: Code-level controls only. Coverage percentages reflect how many framework controls have matching RepoScope detectors. This is a development aid, not a certification tool — auditors make the final determination.

Attestation

I, the undersigned, have reviewed the above assessment and confirm that:

  1. The scope and limitations are understood.
  2. The identified gaps will be addressed per the remediation plan.
  3. Controls outside code scanning scope are managed through separate processes.
  4. I assert that the controls described above are presented in accordance with the applicable Trust Services Criteria.

Name: Dana Lee
Title: Chief Information Security Officer
Signature: ____________________
Date: ____________________