The SOC 2 Confidentiality Default Findings Engine is a requirement-aware template layer for AICPA Trust Services Criteria - Confidentiality. It helps a team define consistent starting language for recurring findings while the normal project remains the source of truth for scope, evidence, ownership, remediation progress, validation, and reports.
Library and standards scope
The Confidentiality category addresses information designated as confidential and the commitments governing its identification, access, protection, retention, and disposal. It differs from the broader Security category and from privacy obligations concerning personal information, although one evidence item may support several control activities.
Global, local, and project layers
- Global defaults are standards-based templates published by voiqq platform owners for a system Library.
- Local defaults belong to the signed-in workspace administrator and can override editable wording without changing the global source.
- A project finding receives copied template values and then becomes an independent record.
- Later global changes do not silently rewrite a local override or a finding already created in a project.
- Status is Open and validation is Pending when the reusable default is applied, unless an authorized project workflow later changes them.
Fields and canonical mapping
Each template is owned by a canonical confidentiality criterion in the SOC 2 Confidentiality Library. The reusable record contains a stable identifier, summary, description, remediation guidance, severity key, mapped values, source Library, and display order. The visible wording can be edited locally, while the background requirement identity continues to support filters, reports, imports, and New Finding suggestions.
Create or customize a default
- Confirm the confidentiality commitments and information categories in scope.
- Select the precise Confidentiality criterion in the local engine.
- Write the default around the failed lifecycle outcome, not a named dataset.
- Describe the evidence a reviewer would expect without embedding that evidence.
- Add remediation covering classification, access, protection, retention, or disposal as appropriate.
- Add system names, data classes, owners, samples, and dates only in the project finding.
Writing rules for reusable findings
Write the summary as a concise statement of the recurring failure. Use the description to explain the expected behavior, likely impact, or control concern in neutral language. Use remediation to describe the desired outcome rather than a patch tied to one framework or customer. Store actual results, reproduction steps, affected assets, evidence, people, dates, measurements, samples, and environment details in the project finding.
Suitable template subjects
- Confidential information is not classified or connected to handling requirements.
- Access to a confidential repository is broader than the approved business need.
- Transfer or storage safeguards do not match the organization confidentiality commitment.
- Retention periods are not implemented or reviewed for confidential records.
- Disposal evidence does not show that confidential information was securely removed.
Use a default in a project
Open New Finding inside a project configured with SOC 2 Confidentiality. Choose Template mode or select a prepared template after choosing the applicable confidentiality criterion. voiqq prefills the reusable values. Review every field, add the real evidence and context, and save the finding. Comments, attachments, assignments, history, validation, sharing, exports, and reports then use the same normal project workflow.
Accuracy and safety checks
- Do not store confidential values, customer names, or access lists in a reusable default.
- Keep Confidentiality and Privacy mappings distinct.
- Avoid absolute legal conclusions.
- Confirm evidence handling follows least privilege.
- Retest access or lifecycle controls before validation.
