So I ended up building my own tool. Nothing magical — just a lot of research, plus layering in the right context (implementation controls, company specifics, testing conditions, etc.).
The outcome: three companies I worked with recently passed SOC 2 Type 2, and the auditors actually called out the policies as well-structured and clear.
You can also try and generate any policies in ~60 seconds
Curious if you’ve run into the same issue and would love your feedback if you give it a spin.
Thank you!