
Startup Trust Pack — SOC 2 + AI Governance
25 editable documents bundling the SOC 2 Core policy set with the full AI Governance pack — answer enterprise security questionnaires AND the new AI-policy questions in one purchase.
New to SOC 2 + AI Governance? Read our SOC 2 + AI Governance guide →
What's inside — 25 documents + 3 workbooks
- Information Security Policy (.docx)
- Human Resources Security Policy (.docx)
- Risk Assessment Procedure (.docx)
- Vendor and Business Partner Management Policy (.docx)
- Access Control Policy (.docx)
- Data Classification and Handling Policy (.docx)
- Encryption and Key Management Policy (.docx)
- Vulnerability Management Procedure (.docx)
- Monitoring and Logging Policy (.docx)
- Security Incident Response Plan (.docx)
- Change Management Policy (.docx)
- Business Continuity and Disaster Recovery Plan (.docx)
- Data Retention and Disposal Policy (.docx)
- Security Awareness and Training Policy (.docx)
- AI Acceptable Use Policy (.docx)
- AI Governance Policy (.docx)
- AI Acceptable Use Policy (.docx)
- AI Risk Assessment Procedure (.docx)
- AI Vendor and Tool Assessment Procedure (.docx)
- AI Data Governance and Privacy Policy (.docx)
- AI Transparency and Disclosure Standard (.docx)
- Human Oversight and Accountability Standard (.docx)
- EU AI Act Readiness Checklist (.docx)
- AI Incident and Model Failure Response Procedure (.docx)
- AI System Inventory and Classification Standard (.docx)
Excel workbooks
- SOC 2 TSC Control Mapping — all 38 criteria (Excel)
- Risk Register (Excel)
- Audit Evidence Checklist (Excel)

See the real content before you buy
We publish genuine excerpts — not marketing mockups. Read the opening sections of the Information Security Policy exactly as you'll receive it:
Read the free previewFrequently asked questions
- What does the Startup Trust Pack combine?
- It bundles the SOC 2 Core policy set with the full AI Governance pack, so you can answer both enterprise security questionnaires and the newer AI-policy questions from a single purchase.
- Why pair SOC 2 with AI governance?
- Enterprise buyers increasingly send AI-use and AI-risk questions alongside their standard SOC 2 security questionnaire. Having both document sets ready lets a startup clear procurement and security review without stalling the deal.
- Does this replace a SOC 2 audit?
- No. It gives you the SOC 2 control documentation and the AI policies; the SOC 2 report itself still comes from an independent CPA firm after their examination.
- What format are the files and how are they delivered?
- Editable Microsoft Word (.docx) and Excel (.xlsx) files, delivered as an instant download immediately after checkout. Organization-specific values are amber [bracketed placeholders] you replace with find-and-replace.
- What licence do I get?
- A single-organization licence. If you are a consultant or MSP intending to reuse the documents across multiple clients, contact us first for a fair multi-client arrangement.
