How to collect soc 2 audit evidence as Small Legal and Compliance Teams
Your two-person legal team is the unofficial owner of SOC 2 audit prep, even though no one in legal has 'compliance engineer' in their title. Every August (or whenever the auditor shows up), you spend two to three weeks manually pulling access logs from Google Drive, chasing the IT team for vendor lists in a spreadsheet that lives in three different versions, re-exporting policy attestation records from Notion, and forwarding evidence folders over Gmail because your shared Drive folder structure was last organized when you had 60 employees. Vanta or Drata tracks control status but doesn't help you actually collect the underlying documents. You're the one who has to go find them.
What you'll set up
Apps, data, and prompts
The combination of Starch apps, the data sources they pull from, and the prompts you use to drive them.
Starch syncs your Gmail data on a schedule (messages, labels, thread history) and syncs your Notion databases on a schedule (pages, users, last-edited timestamps). Google Drive and Slack are connected from Starch's integration catalog and queried live when the evidence tracker or chaser automation runs. HR headcount data (for access review evidence) is pulled from Rippling or BambooHR via Starch's integration catalog. Any vendor portal or compliance questionnaire tool that doesn't have a formal API — such as a customer's self-hosted trust portal — Starch automates through your browser, no API needed.
Step-by-step
See this running on Starch
Connect your tools, describe what you want, and the agent builds it. Closed beta is free.
August 2026 SOC 2 Type I Prep — 6 Weeks Out
| Total controls in scope | 42 |
| Controls with complete evidence on day 1 | 11 |
| Controls auto-flagged as missing by Starch on week 1 | 19 |
| Controls with stale policy docs (>11 months old) | 7 |
| Vendor questionnaire PDFs processed via Email Agent | 14 |
| Hours saved on manual evidence chasing (estimated) | 28 |
Six weeks before your Type I audit window opens, you connect Gmail, Notion, and Google Drive to Starch. Starch ingests your existing Notion controls tracker — 42 rows, each with a control ID and an owner's name — and builds an evidence dashboard in about 90 seconds. Of the 42 controls, 11 already have linked documents in Drive that Starch can verify exist. The remaining 31 are flagged. Starch's first Monday chaser goes out automatically: 19 separate Slack messages, each to the right owner (IT gets the access log requests, HR gets the background check records, Engineering gets the penetration test report). By week 3, you're at 34 of 42 complete without a single all-hands email from you. The 7 policy documents flagged as stale (last attested more than 11 months ago) are routed to policy owners as Task Manager items with a 10-day deadline. Your 14 inbound vendor questionnaires — which arrived as PDF attachments across three email threads — are summarized by the Email Agent in a single session: you learn that 9 of them are answered by your existing policies, 4 need a one-paragraph custom response, and 1 is asking for a control you don't have yet, which you now know before the audit does.
How you'll know it's working
What this replaces
The other ways teams handle this today, and how the Starch version compares.
One platform — task manager, knowledge management, email agent all running on connected data. Setup in plain English; numbers stay current via scheduled syncs and live agent queries.
Try it on Starch →Frequently asked questions
We already use Vanta to track our controls. Does Starch replace it?
Our evidence lives across Gmail, Notion, Google Drive, and a Confluence wiki. Can Starch pull from all of those?
We're not SOC 2 certified yet ourselves. Does Starch have SOC 2 Type II certification?
Can Starch pull our employee access list from Okta or our HR system for access review evidence?
What about evidence that only exists as a PDF attachment someone emailed us?
We have a vendor who only has a trust portal on their website — no API, no email export. Can Starch get their compliance certificate?
The Task Manager app says it's currently in development. Can I use it for audit prep now?
Related guides for Small Legal and Compliance Teams
A Slack announcement sounds simple — you're just telling your team something.
Read guide →A Data Subject Access Request is a formal ask from an individual — a customer, a former employee, a prospect — for a copy of every piece of personal data your business holds on them.
Read guide →Employee offboarding is the set of steps you run every time someone leaves — voluntary or not.
Read guide →Audit and tax workpaper preparation is the annual (or quarterly) exercise of assembling every document your auditors, CPAs, or tax advisors will ask for — reconciled bank statements, categorized transaction ledgers, vendor bills matched to journal entries, payroll registers, fixed asset schedules, intercompany agreements, and the rest.
Read guide →Collect SOC 2 Audit Evidence for other operators
The AI stack built for small IT and ITOps teams.
Read guide →The AI stack built for the founder's office.
Read guide →The AI stack built for small HR teams.
Read guide →The AI stack built for small finance teams.
Read guide →Ready to run collect soc 2 audit evidence on Starch?
Request closed-beta access. Everything is free during beta.