SOC 2 Source Code Compliance

SOC 2 evidence, collected automatically

Codacy runs automated code review and security analysis on every pull request, and the result is recorded on the pull request itself. That record is the evidence SOC 2 CC8.1 asks for.

AICPA SOC certification mark Codacy is SOC 2 Type II certified

Talk to an expert

Trusted by 15,000+ organizations and 200,000+ developers worldwide

Virta Zalando Delivery Hero Bamboo Health Genesys Evolv NASA Fathom Napier LIXIL

How Codacy supports
SOC 2 change management and vulnerability detection

Criterion
What the criterion requires
Codacy's coverage
CC8.1Change Management

Changes are authorised, tested and approved before they are applied

Codacy's quality gate blocks the merge until checks pass and a reviewer approves. The check result and the approval are recorded against the pull request.

CC7.1Vulnerability Detection

Scheduled scanning, severity triage, a documented remediation timeline

Codacy records severity-ranked SAST and dependency findings, identified in code before deployment.

"Codacy has improved communication between security and development teams, and it's continuing to raise the bar for compliance."

David Morton Manager of Security Operations at Genesys

90%accuracy rate in security findings
1,200security issues closed vs a “few hundred” before
900+repositories and 1,400 developers scaled to
David Morton, Manager of Security Operations at Genesys

SOC 2 evidence for engineering leaders

Connect your Git organisation in two clicks. First evidence report the same day.

Change Management

Merge gates with a recorded result

Set the checks a pull request has to pass before it can merge. Each gate produces a timestamped record of what was tested, what the outcome was, and who approved the change. When an auditor samples pull requests, you export those records.

A pull request merge gate showing three successful checks and a passed quality gate
AI Reviewer

Automated review on every pull request

Code review on every pull request, with fix suggestions and PR summaries. CC8.1 accepts manual or automated review. Automated review runs on every change and produces the record without anyone having to write one.

Codacy bot flagging a high risk logical error in a pull request review
Evidence Reporting

Every finding in one dashboard

Security and quality status across your Git organization in a single view. Filter by severity, age and status, and export the result.

Security findings dashboard showing open, critical, overdue and prevented issues

SAST on every commit

Injection flaws, cryptographic misuse, access-control gaps and other high-risk classes, identified before merge.

Open-source dependency scanning

Which packages and versions you depend on, and which carry known vulnerabilities.

Finding age and status

Each finding shows when it was identified and whether it has been resolved. This is the data a remediation timeline is built from.

Enforced coding standards

Configure a rule set once. It is applied at every commit across every repository.

Coverage gates

Set a coverage threshold and enforce it as a merge condition.

Works with your pipeline

Major agents, IDEs and Git providers. Issues sync to Jira, alerts to Slack.

Frequently asked questions

How does Codacy support SOC 2 change management?

Codacy analyses pull requests and reports whether changes meet your configured thresholds. Those results can support your change management evidence alongside records from your other systems.

Can Codacy block a change that fails a check?

Yes, when Codacy status checks are configured as required checks in your Git provider. Your branch protection settings determine whether a failing check prevents a merge.

Is Codacy a complete SOC 2 compliance tool?

Codacy focuses on code quality and application security. Use it within your wider SOC 2 program, alongside your policies, operational controls, and audit process.

See your first evidence
report today

Bring your current process or the questions you are trying to answer. Talk to our team about:

  • The repositories and languages you need to cover
  • The checks you want to apply to code changes
  • The results and records you need for review

Talk to an expert