Unstructured → Evidence → Score

Turn Unstructured Chaos Into Compliance Confidence Join 300+ DevSecOps teams already simplifying audits

Already helping DevSecOps teams reduce audit prep by 30%. We ingest Git, CI/CD, Jira, Slack, and docs; use AI to map unstructured signals to SOC2/ISO/PCI; and deliver audit-ready evidence with a clear risk score.

SDEK CLI

            
SOC2-aligned Read-only connectors BYOK available
450 security teams joined the early-access list this week

Built with input from leading fintech, SaaS, and AI companies

Why now

  • GRC tools check structured settings, but auditors still demand unstructured evidence.
  • Most teams waste weeks screenshotting Jira, Slack, PRs, and CI logs.
  • Underwriters lack objective, evidence-backed risk scoring.

How it works

  1. 1. Ingest

    Connect GitHub/GitLab, CI logs, Jira, Confluence, Slack, HRIS.

  2. 2. Normalize & Map

    AI automatically maps unstructured signals to SOC2/ISO/PCI controls with citations.

  3. 3. Score & Report

    0–100 risk score, deltas over time, one-page audit report, and Jira-ready remediation.

Key features

Unstructured Data Normalization

commits, PR comments, logs, tickets, chats → structured evidence.

Turns raw PR comments, CI logs, and Jira threads into audit-ready evidence.

AI Control Mapping

SOC2 CC6–CC9, ISO Annex A, PCI, HIPAA with explainable rationale.

Explainable control mapping with citations to the original artifacts.

Risk Score & Deltas

quantify posture; show what improves the score.

Quantified risk with clear deltas and 'what-to-fix' guidance.

Audit-Ready Output

one-pager for auditors/insurers with evidence links.

Privacy-by-Design

read-only scopes, redaction, no-exfil mode, BYOK.

Two product paths

CLI for Engineers

brew install sdek → scan Git/Jira/CI, get terminal summary + local HTML/PDF report.

SaaS for Teams

persistent connectors, dashboards, history, benchmarks, API/export to GRC.

Who it’s for

Startups preparing SOC2 Auditors needing real evidence Insurers seeking objective SDLC risk CTOs/DevSecOps

What early adopters are saying

D.M. Head of Security, Fintech Startup

"Finally, SOC2 prep that doesn't mean endless screenshots. Cut our audit prep from 3 weeks to 4 days."

S.K. DevSecOps Lead, SaaS Company

"The AI mapping is surprisingly accurate. It found evidence in Slack threads I'd completely forgotten about."

A.L. CTO, AI Platform

"Risk score dropped 23 points after fixing the Jira tickets it flagged. Our insurer actually noticed."

What's new

Updated October 2025
v0.3.2

SOC2 CC7 Support & Enhanced Logging

  • Full SOC2 CC7 (System Operations) control mapping
  • PagerDuty incident correlation for availability evidence
  • Enhanced CloudWatch/DataDog log parsing
v0.2.8

Jira Evidence Mapping & Smart Citations

  • Automatic Jira ticket → control mapping with confidence scores
  • Deep-link citations to original comments and attachments
  • Support for Jira custom fields in evidence extraction
v0.1.5

GitHub Integration & PR Analysis

  • GitHub/GitLab PR review extraction with approval chains
  • Commit signature verification for change management evidence
  • Branch protection policy compliance checks

Integrations

  • GitHub
  • GitLab
  • Jira
  • Confluence
  • Slack
  • Okta
  • AWS
  • GCP
  • Azure

Design partners

"This reduced our SOC2 evidence collection time by 30%."

Pricing

Free CLI

local scans & report.

Team (SaaS)

dashboards, history, PDF exports, API.

Enterprise

SSO/SAML, BYOK, on-prem agent.

FAQ

Do you store code?

No. We default to metadata + redacted artifacts; no-exfil mode available.

How do you map to SOC2?

AI + rules; each finding cites evidence and control IDs (e.g., CC7.2).

Will this replace my GRC tool?

No—we complement Vanta/Drata by supplying unstructured evidence.

Is there an API?

Yes—export JSON, PDF, and webhooks.

What about insurers?

We provide a quantified risk score and one-page underwriting report.

Ready to turn chaos into confidence?

Download Sample Report

We collect your email only to share product updates and beta access. You can unsubscribe anytime. For security, we default to read-only scopes, redact sensitive data, and offer a no-exfil mode.

Join hundreds of engineers simplifying SOC2 audits

Live Activity