SOC 2 evidence, collected automatically
Codacy runs automated code review and security analysis on every pull request, and the result is recorded on the pull request itself. That record is the evidence SOC 2 CC8.1 asks for.
Codacy is SOC 2 Type II certified
Talk to an expert
Trusted by 15,000+ organizations and 200,000+ developers worldwide
How Codacy supports
SOC 2 change management and vulnerability detection
Changes are authorised, tested and approved before they are applied
Codacy's quality gate blocks the merge until checks pass and a reviewer approves. The check result and the approval are recorded against the pull request.
Scheduled scanning, severity triage, a documented remediation timeline
Codacy records severity-ranked SAST and dependency findings, identified in code before deployment.
"Codacy has improved communication between security and development teams, and it's continuing to raise the bar for compliance."
David Morton Manager of Security Operations at Genesys
SOC 2 evidence for engineering leaders
Connect your Git organisation in two clicks. First evidence report the same day.
Merge gates with a recorded result
Set the checks a pull request has to pass before it can merge. Each gate produces a timestamped record of what was tested, what the outcome was, and who approved the change. When an auditor samples pull requests, you export those records.
Automated review on every pull request
Code review on every pull request, with fix suggestions and PR summaries. CC8.1 accepts manual or automated review. Automated review runs on every change and produces the record without anyone having to write one.

Every finding in one dashboard
Security and quality status across your Git organization in a single view. Filter by severity, age and status, and export the result.

SAST on every commit
Injection flaws, cryptographic misuse, access-control gaps and other high-risk classes, identified before merge.
Open-source dependency scanning
Which packages and versions you depend on, and which carry known vulnerabilities.
Finding age and status
Each finding shows when it was identified and whether it has been resolved. This is the data a remediation timeline is built from.
Enforced coding standards
Configure a rule set once. It is applied at every commit across every repository.
Coverage gates
Set a coverage threshold and enforce it as a merge condition.
Works with your pipeline
Major agents, IDEs and Git providers. Issues sync to Jira, alerts to Slack.
Frequently asked questions
How does Codacy support SOC 2 change management?
Codacy analyses pull requests and reports whether changes meet your configured thresholds. Those results can support your change management evidence alongside records from your other systems.
Can Codacy block a change that fails a check?
Yes, when Codacy status checks are configured as required checks in your Git provider. Your branch protection settings determine whether a failing check prevents a merge.
Is Codacy a complete SOC 2 compliance tool?
Codacy focuses on code quality and application security. Use it within your wider SOC 2 program, alongside your policies, operational controls, and audit process.
See your first evidence
report today
Bring your current process or the questions you are trying to answer. Talk to our team about:
- The repositories and languages you need to cover
- The checks you want to apply to code changes
- The results and records you need for review