# SOC 2 / ISO control mapping template

**Status:** evidence mapping template  
**Non-claim:** this template does **not** assert that CyberHalluciNet is
SOC 2 certified, ISO/IEC 27001 certified, or otherwise attested. Rows are
**control → evidence pointer** mappings for customer assessors.

| Framework topic (example) | Project control / invariant | Evidence / test pointer |
|---------------------------|----------------------------|-------------------------|
| Change management | Propose→Approve→Deploy for agentic desired state | SEC-AG-001, TDD-302/303 |
| Logical access | No attacker authority over policy | SEC-001, transition tests |
| Segregation of duties | Broker-only inference; Ops optional | SEC-003, ADR 0008 |
| System monitoring | One-way telemetry | SEC-004 |
| Vulnerability management | govulncheck, SBOM, VEX, controlled deps | supply-chain-baseline.md |
| Incident response | Out-of-band kill-switch | SEC-009 |
| Availability / DoS bound | Hierarchical budgets | SEC-005 |
| Confidentiality of evidence | Privacy fixture scan; scrub before leave-tenant | TDD-009, SEC-AG-004 |

Fill the “customer evidence date / artifact URL” column (add locally) before
exporting to an ASR packet. Keep this non-claim footer on exports.
