The deal said "SOC 2 or no contract." We build the AWS side of getting there.
Your auditor tests controls. Your compliance platform collects evidence. But somebody has to engineer the access management, logging, change control, and disaster recovery those controls describe — on real infrastructure, running every day of your observation window. That’s us. Fixed price. Senior engineers only.
AWS Managed Service Provider (audited) · Advanced Tier Services Partner · PCI & HIPAA environments in production · Zero client security breaches
You're here because one of these just happened
- An enterprise prospect made SOC 2 Type II a condition of the contract, and the observation window math means you needed to start months ago.
- You bought Vanta or Drata, connected AWS, and the dashboard lit up red — the platform found the gaps, but someone still has to fix them.
- Your readiness assessment came back with infrastructure findings your product engineers have no time to own.
- Your Type I passed on promises; Type II will test whether the controls actually ran for six months.
- Access to production is “the founders have admin,” and you know exactly how that reads in an audit.
Compliance platforms monitor. Auditors attest. Engineers remediate. We’re the third one.
The infrastructure behind the Trust Services Criteria
Access control that survives scrutiny
Least-privilege IAM, SSO integration, MFA enforcement, quarterly access reviews that generate their own evidence, offboarding that actually revokes everything — automatically.
Change management as pipeline, not policy
Every production change through CI/CD with review, approval, and rollback. Terraform for infrastructure means the change log writes itself.
Logging & monitoring
Centralized CloudTrail, GuardDuty, alerting with response runbooks. When the auditor samples a security event, there's a trail and a documented reaction.
Availability & disaster recovery
Backups with tested restores, defined RTO/RPO, multi-AZ architecture. "We have backups" becomes "here's the last restore test and its timestamp."
Vulnerability management
Image scanning in CI/CD, patched baselines, drift correction by code. Findings get closed on a cadence the auditor can sample, not in a panic before fieldwork.
Evidence as a by-product
Controls built into infrastructure produce their own artifacts. Your compliance platform stays green because the underlying reality is green — not because someone screenshots dashboards every quarter.
Fixed price. Built before the observation window, quiet during it.
1. Scoping call — 30 minutes
You tell us the deal timeline and what your readiness assessment or compliance platform is flagging. You leave with a first read on the real infrastructure gaps, whether we work together or not.
2. Gap review against your criteria
We map your AWS environment against the Trust Services Criteria in your scope — Security always, plus Availability or Confidentiality if your customers demand them.
3. Fixed-price remediation
Explicit list of what gets built, priced after discovery. Miss a milestone — you don't pay for that phase. We work alongside your compliance platform, not instead of it.
4. Observation window operations (optional)
Type II is a marathon: controls must run cleanly for 3–12 months. Under our audited MSP practice we operate the environment through the window — access reviews happen, patches land, restore tests run — so fieldwork finds a system, not a scramble.
5. Audit support
When your auditor asks how a control is enforced on AWS, we answer in their language.
We've been passing harder audits for years
SOC 2’s infrastructure controls — access, logging, change management, DR — are a subset of what PCI DSS and HIPAA have demanded of us for over a decade. Payment processors pass annual PCI certification on environments we build and operate. HIPAA telehealth infrastructure runs under our management in production today.
Zero security breaches across every client environment we have ever operated.
Why us, not (just) a compliance platform
The platform finds; we fix
Vanta, Drata, and Secureframe are monitoring layers — they tell you what's wrong. Closing the findings is engineering work on your AWS account. We do that work, and the platform turns green as a result.
No conflict with your auditor
We're not a CPA firm and don't attest. Your auditor stays independent; we're the remediation team on the other side of the table.
Audited ourselves
AWS independently reviewed our operations, security, and incident management before granting the MSP designation. We run our own practice the way your auditor wants yours run.
Senior engineers, founder-led
The people on the call are the people doing the work. No account managers, no juniors learning on your production account.
Auditors: a remediation partner that keeps your independence clean
You can’t engineer the controls you attest. Your clients’ readiness findings need an implementation team that speaks controls language and works fixed-price on AWS. IT-Magic is that counterpart — and your attestation stays yours. For a standing partnership, write to [email protected].
FAQ
Can you get us SOC 2 certified?
SOC 2 isn’t a certification — it’s an attestation report issued by a licensed CPA firm after examining your controls. We don’t attest and never will. We engineer and operate the AWS infrastructure your controls describe, so the examination finds them running.
We already use Vanta / Drata / Secureframe. Why do we need you?
The platform is your evidence and monitoring layer — keep it. But when it flags “MFA not enforced,” “no restore test,” or “over-privileged IAM roles,” those are engineering tasks on your AWS account. That’s the work we do. Platform plus engineers is the complete picture; platform alone is a red dashboard.
Type I or Type II first?
Depends on your deal. Type I proves controls exist at a point in time and can unblock a contract fast; Type II proves they operated over a window and is what enterprise security teams increasingly demand. The infrastructure work is the same — the difference is how long it must run cleanly. We build for Type II from day one so you never do the work twice.
How long until we're audit-ready?
Infrastructure remediation typically runs weeks. The calendar constraint is the Type II observation window (3–12 months, most first reports pick 3–6). The sooner the controls run, the sooner the window starts — which is the strongest argument against waiting.
We're on Railway / Vercel / Heroku and the enterprise deal wants SOC 2. What now?
A common path to us. Shared platforms make some controls hard to evidence — network boundaries, access granularity, log ownership. We migrate your workloads to AWS architecture where every control is yours to demonstrate, without touching your application code.
Can you run the controls during the observation window?
Yes — that’s the MSP model and our core business. Access reviews, patching, restore tests, log retention: they happen on schedule because they’re our job, not your engineers’ side quest.
Thirty minutes, one engineer, your findings list
Bring your readiness assessment or your compliance platform’s red items — or just describe your AWS setup. You’ll leave the call knowing which findings are real infrastructure work, which are paperwork, and what the engineering costs. The read is yours either way.