One of those customers was in the final stretch of a SOC 2 audit. The auditor required evidence of an independent penetration test of their platform, and the audit window left two weeks to produce it.
TaskEngine's team knew the system well and wanted to stay closely involved, so the goal was a fast, collaborative engagement rather than a vendor working alone.
Scoping in the morning, testing the same afternoon
A one-hour scoping session covered the application, the APIs and the repository in scope for the audit. Testing began that afternoon.
Over the next 24 hours Intrudify mapped the environment and ran a full penetration test, while TaskEngine's engineers stayed on a shared channel answering architecture questions and starting follow-up work as results were confirmed. Every result was validated, documented and prioritised before the report was finished.
A package the auditor accepted as it stood
The final report included an executive summary and a remediation tracker, in the structure SOC 2 auditors expect: methodology, scope, results, severity and remediation status in one document.
Intrudify re-tested the follow-up work and issued a closure letter for the audit file. Because TaskEngine was involved throughout, remediation had begun before the report was complete, and every change was independently confirmed.
One of our customers needed a pentest for SOC 2 and the audit was 2 weeks away. We ran it in the morning, they had the report the next day, and the auditor was fine with it.
The outcome
The report and closure letter were accepted as evidence without further requests, and the customer completed its SOC 2 Type II audit on the planned date.
Having seen what a 24-hour turnaround made possible, the customer replaced its previous testing model with a continuous one.
What this evidences
- SOC 2 CC7.1 The report is the testing evidence for this part of the audit; the rest of SOC 2 remains the customer’s own controls and evidence.