PCI DSS-audited mobile POS platform
A mobile POS platform for a UAE fintech that passed a 2025 PCI DSS audit, with controls, access governance, and evidence held to an external assessor's standard.
- 2025
- PCI DSS audit passed
SOC 2 Compliance Automation | SOC 2 Type II
SOC 2 Type II is assessed over an observation period, commonly 6 to 12 months. Every control must operate continuously, with documented evidence for the full window. The evidence already exists in your systems: AWS CloudTrail, GitHub pull request history, Okta access logs, ticketing records. Someone still has to collect it, map it to controls, and hand it to auditors on demand.
We build custom SOC 2 compliance automation: automated evidence collection from your cloud infrastructure and SaaS tools, continuous control monitoring with real-time alerting, policy management with employee acknowledgment tracking, and an audit-ready evidence library that turns weeks of audit prep into hours.
Automated evidence collection from AWS, GCP, Azure, GitHub, Okta, and your SaaS tools, every control documented on schedule without manual collection
Continuous control monitoring that alerts when a control fails the moment it happens, not when auditors discover it weeks later
Policy management portal with version control and employee acknowledgment tracking, so your policy library is always current and always documented
Audit-ready evidence library that auditors access directly rather than you spending weeks assembling packages before each audit
Recent outcomes
Voice AI · Research
6× deeper insights
Text-based interviews converted to automated phone calls
AI Automation · Ops
20k+ txns day one
Manual invoice OCR across 40+ gas stations
Loyalty · Retail
1,062 users in 4 weeks
SuperValu & Centra loyalty platform with receipt validation
SaaS · Logistics
2,000+ shipments yr 1
Multi-carrier shipping hub for Indonesian eCommerce
The problem
Two weeks of manual evidence collection before every annual audit consuming your engineering and compliance team's time for work that should be automated?
Control failures discovered during audit preparation, a stale access review, a missed backup, an IAM misconfiguration, that have been open for months?
Short answer
RaftLabs builds custom SOC 2 Type II automation: evidence collection from AWS, GitHub, Okta, and SaaS tools on a defined schedule; continuous control monitoring that alerts on MFA, public-exposure, and stale-access failures as they occur; policy and vendor workflows; and an auditor-access evidence library. A first evidence-automation module starts around $25,000; a full platform reaches $70,000.
Key takeaways
Trusted by


SOC 2 Type II is not a compliance exercise you complete and put on a shelf. The observation period is continuous. Evidence collection is continuous. Control monitoring is continuous. The audit is the annual moment when a third party examines whether you maintained that continuous posture, and finds the gaps you did not.
The companies that pass SOC 2 Type II with minimal audit preparation time are the ones who automated evidence collection from the start. Their evidence library is already populated when the auditor asks. Control failures were caught and remediated months before the audit. Policy acknowledgments are current because the system enforced them. The audit is a review of an existing record, not an emergency assembly project.
IDC's Business Value of Vanta study (2025) measured compliance-automation users cutting audit-preparation staff time by 82% against manual evidence collection. That figure is specific to one platform's customers, not a general benchmark. The mechanism behind it is general, though: when evidence is pulled on a schedule instead of assembled by hand, the observation period stops eating engineering weeks. For SOC 2 Type II, where evidence must be continuous across the full window, that is the difference between a review of an existing record and an annual fire drill.
Capabilities
Automated pipelines that pull SOC 2 control evidence from your cloud infrastructure and SaaS tools on a defined schedule, covering configuration, access, change management, and availability. Each evidence item is stored with control mapping, collection timestamp, and source, so the evidence library is searchable, auditable, and arrives pre-populated for auditors rather than assembled under deadline pressure.
Real-time monitoring of your SOC 2 control environment with automated alerting when controls fail: MFA disabled for a user, a storage bucket or database exposed publicly, a backup job that failed, an overdue access review, or an offboarded user who retains active access. Control failures are caught when they happen, not during audit preparation when the observation period is already over.
A centralised policy library with version control, approval workflows, and employee acknowledgment tracking. When a policy is updated, acknowledgment requests go out automatically to all affected employees, tracked per person with timestamps and overdue alerts, and new-hire system access is gated on required acknowledgments. Reports export for auditors showing current completion and full history across the observation period.
Structured vendor risk assessment workflows for new vendors and periodic reassessment of existing ones. Questionnaires are distributed automatically when a vendor relationship is created, a risk scoring model calculates inherent and residual risk, and a risk register is maintained from completed assessments, demonstrating that third-party risk is assessed systematically, on schedule, with documented outcomes.
A structured evidence library that organises collected evidence by TSC category and control, with completeness tracking showing which controls have sufficient evidence and which have gaps. An auditor access portal lets the external auditor browse the library directly, reducing email evidence requests during fieldwork, so audit preparation takes hours rather than weeks.
A remediation workflow for control failures identified by continuous monitoring or auditor findings. Each failure creates a task with owner, due date, and severity, tracked from identification through resolution with evidence of the fix documented. Recurring-failure analysis flags systemic issues, demonstrating that control failures are addressed promptly and systematically.
What a report covers
A SOC 2 report scopes one or more of the AICPA Trust Services Criteria. Security is required; the other four are opt-in based on what you promise customers. Automation has to map evidence to whichever criteria you commit to.
Control mapping is the part that decides whether an audit goes smoothly. Each control you commit to maps to a specific evidence source and a collection cadence, and the automation records that mapping so an auditor can trace any control back to its proof. One caveat we say out loud: automated platforms cover the technical evidence layer well, but a meaningful share of SOC 2 controls, management reviews, business-continuity testing, and access-review execution, still need a designed program with named owners and a real cadence. Software surfaces the gap; it does not run the review for you.
Tell us your current control framework, connected systems, and where the manual overhead is highest. We will scope the automation that removes it.
Compliance Automation, full compliance automation capability overview
GDPR Compliance Software, custom GDPR compliance tooling for data subject requests and consent management
Audit Management Software, audit scheduling, evidence management, and finding tracking for internal audit teams
Regulatory Reporting Automation, automated regulatory report generation for regulated industries
Not yet as a published case study, and we would rather say that than dress up unrelated work as compliance proof. The closest thing we can point to is a build that passed a formal external audit against a controls framework. We shipped a mobile point-of-sale platform for a UAE fintech (under NDA) that passed a 2025 PCI DSS audit. It is the same discipline SOC 2 demands: evidence mapped to controls, access governed, and an external assessor satisfied that the controls actually operated. PCI DSS is a different framework from SOC 2, so treat this as adjacent proof of audited-controls delivery, not a SOC 2 report.
Stay on topic

Article
Pharma software development: How to pick a partner
Pharma software isn't regular dev with compliance bolted on. Here's what separates a real pharma tech partner from one that learns GxP on your timeline.
Read more
Article
Tree Service Software: Build Custom or Buy Off-the-Shelf?
Tree service software handles estimating, ISA certification enforcement, equipment scheduling, chemical treatment records, and storm surge dispatch. Here is what custom software costs, when ArboStar or Arborgold stop working, and what a real build looks like phase by phase.
Read more
Article
PCI DSS compliance: Payment security laws for app builders
If your app processes, stores, or transmits credit card data, PCI DSS isn't optional - it's a contract requirement from every payment processor. Here's what the standard requires and how it shapes your app architecture.
Read moreSOC 2 Type I is a point-in-time assessment: an auditor examines your controls at a single date and concludes whether they are suitably designed. Type I answers the question: do these controls exist and are they designed correctly? SOC 2 Type II is an assessment over an observation period, typically 6 to 12 months. An auditor examines evidence that your controls operated continuously throughout the period and concludes whether they are suitably designed and operating effectively. Type II answers the question: did these controls work, consistently, every day, for the full period? Most enterprise customers and procurement teams require Type II because it demonstrates the controls actually operate rather than just existing on paper. Type II is significantly harder to prepare for because the evidence requirement is continuous, not a one-time snapshot. Automation is what makes continuous evidence collection practical at scale.
Evidence collection automation connects to the systems your controls depend on and pulls proof of control operation on a defined schedule. For access control evidence: user access logs from Okta or Azure AD, privilege escalation logs, and quarterly access review records. For change management evidence: pull request approvals and code review records from GitHub or GitLab, deployment logs with approver information, and change ticket records. For configuration management evidence: AWS Config snapshots, infrastructure-as-code state, and security baseline compliance checks. For availability evidence: uptime monitoring records, backup job completion logs, and incident response records. For vendor management evidence: vendor assessment completion records and contract metadata. Each evidence item is stored with its control mapping, collection timestamp, and source metadata. Gaps, missing evidence, failed collection jobs, or controls that have not been checked, surface automatically rather than being discovered by the auditor.
Vanta, Drata, and Tugboat Logic are excellent products for standard control frameworks with typical SaaS infrastructure. If your infrastructure is primarily AWS or GCP, your team uses common SaaS tools the platform integrates with, and your control set follows the standard TSC framework, these platforms will likely serve you well at a lower total cost than custom development. Custom automation makes sense in three situations: your infrastructure includes systems the standard platforms do not integrate with, on-premises servers, custom internal tools, proprietary databases, and the gap requires significant manual evidence collection regardless. Your compliance workflows need to be embedded in your existing internal tools rather than managed through a separate platform. Or your organisation has compliance requirements that go beyond the standard SOC 2 TSC framework, industry-specific controls, custom control families, or multi-framework requirements that the platforms do not handle cleanly. We will tell you honestly during discovery whether a standard platform or custom automation is the better fit for your situation.
A first evidence-automation module starts around $25,000, and the full platform grows to $70,000 over time. Start small: an automated evidence collection pipeline covering the most time-consuming controls (access management, change management, availability monitoring), a basic policy management portal, and an evidence library UI for auditor access. Expand from there to full evidence collection across all TSC categories, continuous control monitoring with alerting, full policy management with acknowledgment workflows, vendor assessment automation, and a compliance dashboard for ongoing visibility. Cost is driven primarily by the number of system integrations required (each connected tool, AWS, Okta, GitHub, Jira, third-party SaaS, adds integration development effort) and the scope of the policy and vendor workflow requirements. We scope the engagement during a discovery phase that assesses your control framework, connected systems, and current manual process.
Work with us
We scope SOC 2 Compliance Automation in 30 minutes. You walk away with a clear cost, timeline, and approach. No commitment required.