Dev.to
7/9/2026

The original title is: "We built a SOC 2 reviewer for AI sessions, and kept AI out of the execution path"
Original: We built a SOC 2 reviewer for AI sessions, and kept AI out of the execution path
Short summary
Chron is an MCP server that records AI coding-assistant actions to a tamper-evident audit trail and reviews them against SOC 2 controls using human-designed, deterministic pattern rules—not AI inference. This preserves auditability: findings are inspectable and dismissible, letting compliance teams govern AI confidently without black-box model decisions.
- •Chron logs all AI session activity (code changes, tool calls, secrets) with hash-chaining and Ed25519 signing, creating an auditable record
- •SOC 2 review uses deterministic pattern rules on structured events, never AI inference, making findings human-reviewable and business-defensible
- •CLI commands filter, accept, dismiss, and resolve findings by control; HTML reports integrate with Vanta, Drata, and Secureframe
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



