
LoxeAI
Auditor-verifiable SOC 2 evidence & mapping in minutes
My mother is an accountant. During high school she'd often disappear during a period called closing (long hours, come home late, go in to work early). The manual strain of compliance was taking a toll on her physical & mental health, as well as her ability to cook food for me & my sister. Me and my sister learned to cook on our own this way.
And she worked for a company thats on the stock market right now. I took a step back & imagined how it was dealing with compliance for lean, pre-series A teams that weren't as equipped & didn't have the resources to invest in black-box tools to help them. There had to be a better way.
It led me down a rabbit hole the past few months, understanding compliance, the trust service criteria, how SOC 2 audits work, type l & type ll, scope, timeframe, the system. I cold-called & dm'ed auditors, CISOs, DevOps, & pre-series A founders around the nation and got in touch with 50 of them.
What I heard was consistent:
->Systems change constantly, so by the time an audit happens, half the evidence is stale
->The big GRC platforms cost $10K–$20K/year and still require significant human effort to operate & don't meaningfully decrease the load.
->Companies without automation systems spend 40-60+ hours manually on the process alone.
->Auditors are increasingly skeptical of automated reports they can't trace back to a source (leading to weeks of back & forth) and potentially hundreds of thousands in lost enterprise deals.
The real problem isn't that automation doesn't exist. It's that the automation is opaque. Nobody can verify where the finding came from, so nobody fully trusts it.
So I built a different approach. Every scan runs as a stateless Cloudflare Worker, no persistent server, no credential caching. Temporary AWS credentials via STS AssumeRole, evidence collected, process exits. Every finding in the report traces back to the exact API call that produced it, SHA-256 hashed, so an auditor can verify it themselves.
The evidence layer is fully open-source. The goal is to give lean AWS-native teams a pre-audit readiness tool they can actually trust, and actually afford.
Repo: github.com/adog0822/AWS-Evidence-Layer
For SOC 2ers: Genuinely curious whether this changes anything in your workflow, or if I'm solving the wrong part of the problem. Honest feedback welcome.
About
Today, companies assemble manual or loosely automated evidence for systems that constantly change, so audits are slow & mistrusted. I’m building verifiable infrastructure rooted in APIs, so it cant be faked/inaccurate.

Comment