LoxeAI
Auditor-verifiable SOC 2 evidence and mapping in minutes
Loxe is an open-source AWS evidence collection tool for SOC 2 audits. It scans your AWS environment using a read-only role, maps findings to SOC 2 controls, generates freshness and gap detection scores, and records the exact API calls, timestamps, and regions used to produce evidence so auditors can independently verify results. Teams can run a free scan for a gap report and then purchase a one-time deeper report with traceable evidence and control analysis.
The paid report also includes Gideon, a compliance copilot that helps teams prioritize fixes, generate AWS policies and CLI commands, maintain a risk register, and prepare for auditor questions using findings from their scan.