Dev.to
6/29/2026

Open-Source Customizable Compliance
Short summary
A Northeastern student built an open-source AI compliance agent that automates SOC 2 evidence collection and auditor reporting for early-stage SaaS, Fintech, and Healthtech teams using AWS and Github infrastructure. The tool customizes controls to match company-specific policies and generates cryptographically verifiable reports with tamper-evident chains of custody. Designed for lean teams (1–30 members) undergoing their first SOC 2 Type I audit.
- •Automates SOC 2 compliance evidence collection from AWS/Github infrastructure
- •Customizable controls tailored to company-specific policies
- •Tamper-evident audit reports with SHA-256 chains of custody
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



