PROTOCODE
S-04 compliance readiness rev C ISO/IEC 27001 · SOC 2

Ready for the audit, from the architecture up.

An enterprise customer asks for SOC 2 or ISO/IEC 27001. The controls they ask about have to exist in your architecture, your infrastructure and the way your team works. We build them there, and document them so an auditor can follow.

01 scope rev C what readiness covers

Four kinds of work.

  1. PoliciesSecurity policies that describe what your team actually does, not a template it will never follow.
  2. DocumentationSystem and architecture documentation an auditor can read and match against the running system.
  3. Technical controlsThe controls themselves, in your cloud and your services: access, network exposure, backups and recovery.
  4. EvidenceEvidence collected automatically where possible, so it is ready when the audit asks for it.
02 in practice rev C current project

What it looks like on a real platform.

We are taking a SaaS platform through readiness aligned with ISO/IEC 27001: security policies, system and architecture documentation, and the technical controls behind them across AWS and the back-end microservices. Readiness work, not audit or certification.

checks in place

  • Unused services disabled
  • Inbound traffic limited to the CDN
  • SSH access → AWS Session Manager
  • Evidence collected automatically

project

context
SaaS platform · AWS, Terraform, microservices
period
Aug 2026 – ongoing
role
Technical Lead
Project details →
03 fit rev C who it is for

Made for SaaS teams led by engineers.

It fits best when the platform runs on AWS and the team would rather build real controls than fill in spreadsheets. Because we also build software and run cloud infrastructure, the controls end up in the system itself, where they keep working after the audit.

04 limits rev C what this work is not
readiness, not audit or certification

We get you ready. An independent auditor does the audit.

ProtoCode is not an audit firm, a CPA firm or a certification body. We do not perform audits, we do not certify companies, and we do not issue certificates or audit opinions.

A SOC 2 report comes from an independent CPA firm. ISO/IEC 27001 certificates come from certification bodies, not from us. You choose and engage the auditor; our part ends with a platform that is ready for them.

05 next step rev C

Tell us what your customer asked for.

The framework, your timeline, and where the platform runs. We reply within one business day.

write to
hello@protocode.rs

reply
Within one business day
studio
Zrenjanin, Serbia
works
Remote only, mostly international clients, open to clients anywhere
time zone
Belgrade (CET/CEST)