You'd think SOC2 needs a $30k consultant and a dedicated compliance hire — Tycoon Agent has the gap report and 12-week roadmap ready in an afternoon.
The short answer
Tycoon Agent answers "walk me through SOC2 prep" by running a full gap assessment against the 64 Trust Service Criteria controls in your first session. She connects to Vanta or Drata if you have one, scans your GitHub for branch protection and code review enforcement, audits your AWS/GCP IAM for least privilege, checks your HR system for background checks and offboarding, and inventories vendors needing security questionnaires. The output is a Notion playbook: which controls already pass, which need policy docs (she drafts 18 of them — Access Control, Incident Response, Change Management, etc.), which need infra changes (MFA enforcement, log retention, encryption at rest), and the 12-week sequence to close gaps. She schedules the auditor selection call by week 4 and the Type 1 audit start by week 12. You stop guessing what SOC2 actually requires.
How Tycoon Agent actually does it
- Run a gap assessment
Connect Vanta or Drata if available; otherwise audit GitHub, AWS/GCP, Okta/Google Workspace, and your HR system manually. Score each of 64 controls pass/partial/fail.
VantaDrataGitHubAWSOkta
- Draft the 18 required policies
Access Control, Incident Response, Change Management, Risk Assessment, Vendor Management, Data Classification, Backup, Encryption, BCP/DR, etc. — all in Notion, all reviewable by counsel.
Notion
- Sequence the infra fixes
MFA enforcement, log retention to 1 year, encryption at rest verification, branch protection on main, code review enforcement, vulnerability scanning. Ordered by effort + audit weight.
- Manage vendor questionnaires
Identify subprocessors, send security questionnaires, collect their SOC2 reports, file in vendor management system.
VantaOneTrustNotion
- Schedule and own the audit
Shortlist 3 auditors (A-LIGN, Prescient, Johanson), book intro calls, select by week 4, kickoff Type 1 audit by week 12. Calendar holds and prep docs delivered before each call.
Google CalendarLark
What it looks like in chat
YouWalk me through SOC2 prep. We have 6 months before our biggest customer requires it.
Tycoon AgentRan the gap scan. **38 of 64 controls already pass** (you have Vanta wired and GitHub branch protection on). **18 need policy docs only** — I'll draft these in Notion this week. **8 need infra work**, in order: 1. Enable MFA on AWS root + IAM (1hr) 2. Extend CloudWatch log retention to 365 days (~$180/mo cost) 3. Encrypt RDS at rest — already on, just need evidence screenshot 4. Add branch protection to `infra` repo (10 min) 5. Quarterly access review automation in Vanta (2 hrs setup) 6. Vendor questionnaires to your 11 subprocessors (I'll handle outreach) 7. Security awareness training in BambooHR (assign + track) 8. Incident response tabletop exercise (schedule in May) **Auditor selection:** I'll send 3 quote requests today (A-LIGN, Prescient, Johanson). Type 1 audit kickoff: week of June 16. Type 2 observation: 6 months after. Your customer's deadline is achievable. Want me to start the policy drafts now?
What you get back
A Notion workspace with the gap assessment, 18 drafted policies, the 12-week sequenced roadmap, vendor management tracker, auditor shortlist with quotes, and Google Calendar holds for every milestone.
Cadence: One-shot for the assessment, then weekly progress reviews through the 12-week prep, then quarterly evidence collection during Type 2 observation.