What problem does it solve? Organizations pursuing security certifications struggle to translate framework requirements into working controls, collect audit-ready evidence, and remediate gaps before external auditors find them. ## Core Features & Use Cases - Gap Assessment: Evaluate current security posture against SOC 2, ISO 27001, HIPAA, or PCI-DSS control objectives and produce prioritized remediation roadmaps with effort estimates. - Controls Implementation: Design technical controls and automated evidence collection pipelines that fit existing engineering workflows. - Audit Execution Support: Organize evidence packages by control objective, run internal audits, and track findings through verified closure. - Use Case: A startup preparing for its first SOC 2 Type II audit uses this Skill to map existing controls, identify that shared AWS credentials violate CC6.1, and build a remediation plan with an evidence collection matrix. ## Quick Start Ask the agent to run a SOC 2 gap assessment on your current access control and monitoring practices and produce a prioritized remediation roadmap.