AICPA SOC Licensed SOC 2 auditor
Open source

SOC 2®
goes agentic

We drive the collapse of SOC 2 cost.

2011
$80,000
SOC 2 is born
2017
$50,000
Criteria modernized
2020
$20,000
Prep became software
2026
$3,000
Done in your AI

Say “Start SOC 2” in your AI.

claude mcp add --transport http chiaro https://mcp.chiarohq.com/mcp

Paste into Claude Code → /mcp → authenticate chiaro.

Who we serve

Built for AI builders.

If you ship with AI, your audit should work the way you do.

You stay in your IDE.

Get your full-cycle SOC 2 done inside your own AI coding tool through the Chiaro MCP. Claude Code, Codex, Cursor, whatever you build with.

Works with
The platform

All in one platform.

We don’t sell productivity. We deliver the outcome. Because we’re MCP-native, you get the whole thing done from your own AI, with nothing new to learn.

Your terminal
acme — claude
Claude Code
Claude Codev2.1.219
Opus 5 with xhigh effort · Claude Max
~/acme
esc to interrupt◉ xhigh · /effort
Your Chiaro portal
app.chiarohq.com/controls
Your terminal
acme — claude
Claude Code
Claude Codev2.1.219
Opus 5 with xhigh effort · Claude Max
~/acme
esc to interrupt◉ xhigh · /effort
Your Chiaro portal
app.chiarohq.com/controls
Your terminal
acme — claude
Claude Code
Claude Codev2.1.219
Opus 5 with xhigh effort · Claude Max
~/acme
esc to interrupt◉ xhigh · /effort
Your public trust page
verified.acme.com
How it works

Getting started, step by step.

Zero learning curve. No prior SOC 2 knowledge required.

1

Create your account

Free for 30 days. Nothing to install.

Start 30 days free
3 min
2

Connect your AI

Connect your own AI coding tool to our MCP.

3 min
3

Run readiness

Readiness runs inside your AI, guided by our MCP.

30-50 hours
4

Submit evidence

Chiaro collects your evidence through your AI, with your approval.

10-30 hours
5

Get your report

Our audit team reviews it, performs the audit, and issues your report.

3-5 days

See what you get.

Everything you would expect in a SOC 2 report, on a fictitious company.

Download a sample report
Open source

Trust shouldn’t be a black box.

Chiaro is open source. How we work is public. Trust what you can verify, not what you’re told.

Human in the loop

Hard-earned depth.

We’re builders too. We just happen to be SOC 2 experts.

Founders

Founded by domain experts.

Yuanlun Yin
Yuanlun Yin ex-Deloitte SOC 2 domain expert. Dual-licensed CPA, California + Texas.
Lan Yin
Lan Yin ex-TikTok, ex-Raymond James. McCombs MBA, UT Austin.
PreviouslyDeloitteTikTokRaymond James

Depth

Battle-tested fieldwork.

Yuanlun led 30+ SOC 2 engagements across the US and Canada at Deloitte, working with category-defining companies like LinkedIn, Ripple, and Affirm, and led SOC 2 trainings firmwide.

Community

Where founder pain lives.

We’re deeply embedded in the founder community across the US and Canada. Hundreds of conversations with founders shaped Chiaro, and we keep building where the pain is sharpest.

Pricing

Transparent pricing.

You pay what you see. No hidden costs.

Team size

Which audit?

Trust criteria

Add-ons

$468

Readiness

  • Find and fix your gaps
  • Zero learning curve
  • Done in your own AI
Your time 30-50 hours
$2,000

Audit

  • Evidence collected automatically
  • Industry-trusted methodology
  • Done in your own AI
Your time 10-30 hours
Included

Trust Center

  • GEO-optimized
  • Live on day one
  • Auto-fills security questionnaires
Why is this so much cheaper than everyone else?

Your AI is already smart enough to handle SOC 2 prep. What it doesn’t have is the guardrails: what counts as evidence, what a control actually needs, where an auditor will push. That’s what we give it, and we ride the AI to do the rest. So there’s no reason left to pay a compliance platform $10,000 a year for prep. We bring that down by 95%.

Same for the audit. We cut the human work that never needed a human, collect your evidence right inside your own AI, and keep a licensed auditor on the judgment. Better quality, faster, and a fraction of the price.

And if you’d rather not take our word for any of it, don’t. Our entire audit methodology is open source and battle tested. It’s all on GitHub: what we test, what counts as evidence, what passes and what doesn’t. Verify it yourself, dig as deep as you want.

How do you make money?
Two ways. A one-time readiness fee for the Chiaro platform, which covers getting you audit-ready and keeps your controls monitored. And the audit itself, which we run as a licensed CPA firm, so you pay us directly. Your Trust Center comes free with any audit. Nothing recurs. The readiness fee is about 95% cheaper than the big compliance platforms, and there’s no separate auditor marking up the audit. No data resale, no hidden fees.
Is Chiaro really open source?
Yes, the real thing. Not a summary, not a cleaned-up version for show. It’s the exact methodology we run on every engagement, published on GitHub, and you can read all of it before you pay us a cent. The only things not in the repo are the platform itself and the exact phrases our anti-gaming gates match on, and the README says so.
If you help me get ready and then audit me, how is that independent?

We designed our process specifically to comply with the AICPA’s newest independence rules, effective June 2026. Doing readiness and then the examination for the same client is explicitly permitted (ET 1.295.040) and is normal practice across the profession. You make every decision and you own your controls. That is written into our engagement letter, so your security team can read it there.

The platform is what keeps it clean in practice. Readiness runs inside your own AI, on your own machines, so control design stays yours. We tell you what is missing and what good looks like; you build it. At the audit we collect the evidence fresh and examine what you built. The full mechanism and citations are in the Field Manual write-up.

How does the MCP connection work?
MCP is just the standard way today’s AI tools connect to outside services. You add Chiaro to the AI tool you already use, like Claude or Cursor, in one line. After that you talk to it in plain English, and it does the work with you: gathering what’s needed from your own systems, checking it, and pointing out what to fix. Nothing leaves your machine unless you approve it, and there’s nothing new to learn.
Do I need a separate evidence collection tool?
No. Chiaro collects the evidence for you, automatically, through your own AI. There is nothing else to buy or connect.
Is Chiaro all in one?
Yes. It finds your gaps, guides you through the fixes, collects the evidence, manages the audit engagement and billing, and publishes your trust center. One product, start to finish, inside the AI tool you already use.
Can I use my own auditor?
Of course. The Chiaro platform is yours, and you can take your work to any auditor you like.
What if I’m a solo founder or a tiny team?
This is exactly who we built Chiaro for. We shape everything around how your team actually works, instead of forcing you into controls and paperwork meant for a big company. You won’t have to invent an org chart, approvals, or processes you don’t really have. You get a real, honest report that holds up, sized to a team like yours.
What if I’m not ready, or know nothing about SOC 2?
That’s where most people start, and it’s completely fine. You don’t need to know anything about SOC 2 or have anything in place first. Chiaro looks at how you run things today, tells you in plain terms where the gaps are, and walks you through fixing them one step at a time until you’re ready for the audit. You make the calls. We tell you what good looks like.
Can I skip readiness and go straight to the audit?
Yes. When you create your account, pick the audit instead of starting the readiness trial, and you skip the readiness fee entirely.

Just know that there’s no prep step to fix things first, so anything we find during the examination goes in your report as an exception. If your controls are already in place, that’s fine. Most teams run readiness first.
How do the free trial and refunds work?
Start with 30 days free, with full access. Cancel before the 30 days are up and you are never charged. After that the readiness fee is a single charge, and you can stop before any audit charge you have not paid yet. We’d rather you leave than feel stuck.
Where are you based, and who regulates you?
We’re US-based, in Austin, Texas. Chiaro is a product of Y Assurance PLLC, a licensed CPA firm regulated by the Texas State Board of Public Accountancy (Firm Registration No. C12398), working under AICPA attestation standards. We’re enrolled in the AICPA Peer Review Program, the profession’s own quality check on firms that issue reports like these. Our founder is a dual-licensed CPA in California and Texas. Want to verify any of it, or need more from us? Just ask us.