How Certivar works
Eight stages, from the first conversation to the package your auditor opens. Two of them are people, on purpose.
The engagement
You are involved in three of these: the interview, approving the scope, and the handful of tasks only a person can do.
We interview you
A structured conversation, not a form. What you build, what you run it on, what data you hold, who your customers are, and why you need the certification. It takes about ten minutes and it is the input to everything that follows.
You get: A scope profile: your stack, your data, your drivers.
We scope the program
We work out which frameworks apply, which controls genuinely do not, and what has to happen before you are ready. Every Not Applicable decision carries a written rationale, because an auditor will ask and a thin answer is worse than no answer. The timeline is calculated from the framework's real constraints.
You get: A scope proposal with frameworks, N/A rationales, human tasks and a date.
A person reads it before you do
The proposal does not go straight to you. A Certivar reviewer reads it first and can approve it, edit it, or reject it with a reason that goes back into the system. This is the gate that everything attesting passes through.
You get: A reviewed proposal, released to you.
You approve the scope
You are the accountable party, so adopting the scope is your decision, made by a named person. Approving it adopts the frameworks, applies the N/A rationales to the controls, opens your task list and starts the policy work.
You get: A live program, moving into remediation.
We write your policies
Each policy starts from a baseline and is rewritten against your real stack and named systems. The draft is compared against the baseline it came from, and one that has not meaningfully diverged is rejected rather than shipped. You see the baseline, the diff, and what changed and why.
You get: A policy set, each version bound to a SHA-256 digest.
We connect to your systems
Read-only API connections to your cloud, source control and identity providers. Scoped, revocable, and logged by the provider. Nothing is installed on anything you own.
You get: Continuous test results, mapped to controls.
We run every morning
The daily loop reviews test results, proposes evidence for the controls it supports, opens tasks for anything only a person can do, updates your readiness, and writes a short report citing what it was based on. Evidence is never attached to a control automatically — a reviewer approves that mapping.
You get: A moving readiness score and a short list of things we need from you.
We deal with your auditor
Your auditor gets their own portal with scoped read-only access. Their information requests get drafted responses built only from verified artifacts. The audit package is assembled from database state, not written by a model: every file hashed, every N/A carrying its rationale, every gap listed as a gap.
You get: An evidence package your auditor can check rather than take on trust.
Two different things are called “agents”
We say nothing gets installed on your systems. We also say Certivar is built on AI agents. Those are not in tension, but the word is doing double duty, so here is the distinction in plain terms.
Monitoring agents — we don't use these
Software a compliance vendor installs on your servers and laptops, running permanently to watch them. This is what Vanta, Drata and similar tools deploy.
- Runs on machines you own, usually with elevated privileges
- Sees whatever is on the host, including customer data and source code
- Consumes resources on production systems
- Is another way in if the vendor is breached
- Often needs a security exception before it can be approved at all
AI agents — this is how we do the work
Models given tools and a task. They conduct the intake interview, scope the program, draft your policies, review test results and answer questionnaires.
- Run on our infrastructure, never on yours
- Reach your systems only through read-only API connections you authorised
- Cannot store a claim that does not cite resolvable evidence
- Are supervised — a person approves anything that attests
- Leave an append-only record of everything they did
So: no monitoring software on your machines, and yes, a great deal of AI on ours. We would rather say both plainly than let “no agents” imply we are not an AI company. We are — that is the product.
What stops the AI making things up
This is the part that matters, and it is a fair question to ask of anyone selling AI-generated compliance evidence. Four things are true of every Certivar engagement.
A claim without evidence never gets stored
Anything that attests to a fact about your company has to cite artifacts that resolve inside your account. If the citation does not resolve, the write is rejected. This is enforced in code, not in a prompt, and not reviewed after the fact.
A person signs anything that attests
A Certivar reviewer approves before it leaves us. A named person at your company approves before it counts as your attestation, bound to the exact content hash they saw — not to the document title.
Every action is logged and readable
The AI's actions go to an append-only record: what it did, what it was based on, which model, how confident, who reviewed it and when. You can read it. So can your auditor.
We will not move a date to win the work
A SOC 2 Type II observation window cannot be shortened by anyone. If your deadline is not achievable, we say so before you pay, and we propose the route that is.
