Compliance Matrix

SOC 2 Trust Services Criteria Mapping Matrix

This matrix aligns MarketMind AI's cloud infrastructure, security controls, and operational policies with the AICPA SOC 2 Trust Services Criteria.

Last updated: August 2026

Security (Common Criteria CC1–CC9)

Scope & AICPA Requirements

CC6: Logical & Physical Access — Access restrictions, credential management, least privilege.

MarketMind AI Control Implementation
  • •GCP IAM & RBAC: Fine-grained service account permissions enforcing Principle of Least Privilege.
  • •Secret Manager: Runtime injection of API keys and database strings; zero hardcoded secrets.
  • •Network Boundaries: Isolated VPCs with Cloud NAT and Private Google Access; no direct public access to database nodes.
Scope & AICPA Requirements

CC7: System Operations — Vulnerability monitoring, incident detection, anomaly alerts.

MarketMind AI Control Implementation
  • •Observability: Centralized GCP Cloud Audit Logs tracking all administrative and API events.
  • •Automated Alerts: Pub/Sub thresholds and Cloud Monitoring alerts for anomalous API egress or quota spikes.
Scope & AICPA Requirements

CC8: Change Management — Version control, testing, deployment safety.

MarketMind AI Control Implementation
  • •Terraform IaC: 100% of cloud resources provisioned via version-controlled code repos.
  • •CI/CD Guardrails: Automated Cloud Build/GitHub Actions pipelines for dry-run plans (terraform plan) prior to production execution.

Availability (A1.1–A1.3)

Scope & AICPA Requirements

Infrastructure Resilience — Uptime, disaster recovery, capacity management.

MarketMind AI Control Implementation
  • •Serverless Cloud Run: Auto-scaling containerized microservices across multi-zone GCP regions.
  • •Database Backups: Automated, point-in-time recovery (PITR) enabled on Cloud SQL instances.

Confidentiality (C1.1–C1.2)

Scope & AICPA Requirements

Data Protection & Disposal — Encryption, tenant segregation, secure purging.

MarketMind AI Control Implementation
  • •Data at Rest/Transit: Enforced AES-256 via GCP KMS and TLS 1.3 across all microservices.
  • •Tenant Memory Isolation: Schema-level separation in Cloud SQL (pgvector) preventing cross-tenant vector contamination.
  • •Secure Deletion: Automated 30-day purge workflow for tenant memory indexes upon contract termination.

Processing Integrity (PI1.1–PI1.5)

Scope & AICPA Requirements

AI Output Validity & Execution — Input validation, pipeline completeness, error handling.

MarketMind AI Control Implementation
  • •LiteLLM Gateway: Centralized routing, schema validation, rate-limiting, and error-handling on LLM API calls.
  • •Auditability: Complete transaction tracing from user input prompt to agent tool execution.

Privacy (P1–P8)

Scope & AICPA Requirements

Data Usage & Rights — Notice, choice, usage limits, zero training.

MarketMind AI Control Implementation
  • •Zero Model Training Mandate: Contractual and technical routing via Google Vertex AI enterprise endpoints with zero prompt retention.
  • •Zero Third-Party Scraping: Customer data is strictly restricted from public LLM training or external data mining.

Audit Readiness & Certification Strategy

Inherited Compliance

Physical, environmental, and hypervisor controls are inherited directly from Google Cloud Platform's SOC 2 Type II, ISO/IEC 27001, and HIPAA BAA-eligible frameworks. MarketMind AI itself is not currently HIPAA-compliant.

Roadmap

MarketMind AI is configured via Infrastructure as Code (Terraform) to enable automated continuous compliance tracking (via platforms like Vanta or Secureframe) ahead of a formal SOC 2 Type I audit post-seed round.

We use cookies

We use essential cookies to make our site work, and optional analytics cookies to understand how you use it. See our Privacy Notice and Terms.