GRC PROS

GRC PROS

Use Cases

Use Case: Applying Serverless GRC Lessons with AI During SOC 2 Type 2 Preparation

Mar 26, 2026
∙ Paid

Person working at desk with laptop and phone.

A B2B SaaS company that provides workflow automation tools for mid-market enterprises operates its entire platform on AWS serverless services, including AWS Lambda for compute, Amazon API Gateway for endpoints, Amazon DynamoDB for data storage, Amazon EventBridge for event routing, and AWS Step Functions for complex orchestration.

The platform handles customer PII and some financial data, placing it within the scope of SOC 2 Type 2 attestation for the Security and Confidentiality criteria.

As the company prepared for its first SOC 2 Type 2 audit, the GRC and engineering teams encountered challenges directly tied to the characteristics of serverless architectures.

Evidence for controls had to be assembled from transient function invocations, event payloads, execution traces, and configuration states rather than persistent server logs.

Maintaining an accurate inventory of hundreds of resources was complicated by frequent product changes. Infrastructure-as-code (IaC) served as the primary…

User's avatar

Continue reading this post for free, courtesy of Alex Seven, GRC Consultant.

Or purchase a paid subscription.
© 2026 A3INFOSEC LLC · Publisher Privacy ∙ Publisher Terms
Substack · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture