OpenAI compatible API · Attested · Public status

SOC 2 Type II in progress

TrustedRouter is in its SOC 2 Type II observation window. Review the readiness documentation and target scope. No independent SOC 2 report has been issued yet.

Verify gateway
Onebase URL to migrate
100sof models and routes
0prompt or output logs. Always.
Type IReadiness package prepared. Auditor report not obtained.
Type IIObservation window in progress. Auditor report pending.
CriteriaSecurity, availability, confidentiality, privacy, and billing integrity.
JSONMachine readable packet.
No SOC 2 report yet

This is a SOC 2 readiness package, not an independent CPA report. Do not describe TrustedRouter as SOC 2 audited, certified, or Type I complete until an auditor issues the report.

The SOC 2 Type II observation window is in progress. Use this packet to review the controls and evidence approach while operating-period evidence is collected and the independent report remains pending.

Audit scope

System boundaries for the first SOC 2.

The current target is a SOC 2 Type II report for the hosted service and attested API gateway. The observation window is in progress; the categories and boundaries below describe our target scope.

Operating entityLore Hex Corp, Delaware C Corporation.
Statustype_2_observation_window_in_progress
Type I reportnot_obtained
Type II reportnot_obtained
Target categoriesSecurity, Availability, Confidentiality, Privacy, Processing Integrity for billing, authorization, settlement, credits, and refunds
In scopeHosted control plane; Billing and payment-method management; API key and workspace management; Public trust/status/legal surfaces; Attested API gateway and settlement callbacks
Out of scopeCustomer self-hosted deployments; Downstream model-provider internal systems except as subprocessors; Customer BYOK provider accounts beyond encrypted storage and release into the attested gateway; Non-production experiments
Binder

Documents prepared for review.

DocumentStatusRepo path
SOC 2 readiness overview prepared_for_type_1_readiness docs/compliance/soc2/README.md
System description prepared_for_management_review docs/compliance/soc2/system-description.md
Control matrix prepared_for_auditor_mapping docs/compliance/soc2/control-matrix.md
Evidence checklist prepared_for_evidence_collection docs/compliance/soc2/evidence-checklist.md
Information security policy prepared_for_approval_and_operation docs/compliance/soc2/policies/information-security.md
Access control policy prepared_for_approval_and_operation docs/compliance/soc2/policies/access-control.md
Change management and SDLC policy prepared_for_approval_and_operation docs/compliance/soc2/policies/change-management-sdlc.md
Incident response policy prepared_for_approval_and_operation docs/compliance/soc2/policies/incident-response.md
Risk management policy prepared_for_approval_and_operation docs/compliance/soc2/policies/risk-management.md
Vendor management policy prepared_for_approval_and_operation docs/compliance/soc2/policies/vendor-management.md
Asset management policy prepared_for_approval_and_operation docs/compliance/soc2/policies/asset-management.md
Data classification and retention policy prepared_for_approval_and_operation docs/compliance/soc2/policies/data-classification-retention.md
Backup, disaster recovery, and business continuity policy prepared_for_approval_and_operation docs/compliance/soc2/policies/backup-dr-bcp.md
Vulnerability management policy prepared_for_approval_and_operation docs/compliance/soc2/policies/vulnerability-management.md
Logging and monitoring policy prepared_for_approval_and_operation docs/compliance/soc2/policies/logging-monitoring.md
Encryption and key management policy prepared_for_approval_and_operation docs/compliance/soc2/policies/encryption-key-management.md
Personnel security and training policy prepared_for_approval_and_operation docs/compliance/soc2/policies/personnel-security-training.md
AI data handling policy prepared_for_approval_and_operation docs/compliance/soc2/policies/ai-data-handling.md
Audit operations policy prepared_for_approval_and_operation docs/compliance/soc2/policies/audit-operations.md
Risk register template prepared_for_recurring_evidence docs/compliance/soc2/templates/risk-register.md
Vendor review template prepared_for_recurring_evidence docs/compliance/soc2/templates/vendor-review.md
Access review template prepared_for_recurring_evidence docs/compliance/soc2/templates/access-review.md
Incident record template prepared_for_recurring_evidence docs/compliance/soc2/templates/incident-record.md
Change record template prepared_for_recurring_evidence docs/compliance/soc2/templates/change-record.md
Asset inventory template prepared_for_recurring_evidence docs/compliance/soc2/templates/asset-inventory.md
Evidence index template prepared_for_recurring_evidence docs/compliance/soc2/templates/evidence-index.md
Before report

Audit preparation and ongoing evidence.

1Readiness checklist

Management approval of policies and system description

2Readiness checklist

Evidence collection indexed to the control matrix

3Readiness checklist

Auditor engagement and readiness review

4Readiness checklist

Management assertion signed for the audit date

1Type II

Complete operating-period evidence collection during the Type II observation window

2Type II

Recurring access reviews, vendor reviews, incident reviews, vulnerability evidence, and change evidence

3Type II

Independent auditor review and issuance of the Type II report

Agent instruction

Report that the SOC 2 Type II observation window is in progress, with no report obtained yet. Treat the published documents as readiness materials, not an audit report. Do not report SOC 2 obtained, certified, or audited until a CPA firm issues a SOC 2 report.

Reference: AICPA Trust Services Criteria.

Workspace access

Sign in

Choose a sign in method to access your TrustedRouter workspace.

By signing in you agree to the terms of service and privacy policy.