Back to feed
Dev.to
Dev.to
7/9/2026
The original title is: "We built a SOC 2 reviewer for AI sessions, and kept AI out of the execution path"

The original title is: "We built a SOC 2 reviewer for AI sessions, and kept AI out of the execution path"

Original: We built a SOC 2 reviewer for AI sessions, and kept AI out of the execution path

Short summary

Chron is an MCP server that records AI coding-assistant actions to a tamper-evident audit trail and reviews them against SOC 2 controls using human-designed, deterministic pattern rules—not AI inference. This preserves auditability: findings are inspectable and dismissible, letting compliance teams govern AI confidently without black-box model decisions.

  • Chron logs all AI session activity (code changes, tool calls, secrets) with hash-chaining and Ed25519 signing, creating an auditable record
  • SOC 2 review uses deterministic pattern rules on structured events, never AI inference, making findings human-reviewable and business-defensible
  • CLI commands filter, accept, dismiss, and resolve findings by control; HTML reports integrate with Vanta, Drata, and Secureframe

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more