An audit-ready status page

ISO 27001 and SOC 2 ask you to show how you communicate incidents to customers. A timestamped page proves it without extra work.

Where the requirement comes from

No standard names a tool — they ask for evidence:

  • SOC 2 CC2.3: communicating incidents to external parties
  • ISO 27001 A.5.5 and A.5.24: interested parties and incident management
  • Customer contracts with a public uptime figure in them

Why documents are not enough

A written procedure

It shows intent, not action. The auditor asks what it looked like during the last incident.

An email archive

The evidence exists, but you assemble it by hand before every audit, and the recipient list is never complete.

An internal incident tool

Excellent for the team and silent to the outside — and the outside is what is being asked about.

What the auditor gets

Timestamps you did not have to write

Every report and update is timestamped automatically and stays in the archive.

Proof that you told people

Subscriber notifications are recorded, and maintenance is announced ahead of time with start and end.

An audit log

Every change in the workspace — who, what, when — including what an AI assistant did through MCP.

Retention periods

Retention is written into the plan and the data stays in the EU, which answers the next question on the list.

Getting ready

  1. 1Create a public page on your own domain
  2. 2Name your components and attach monitors
  3. 3Set up subscriptions for interested parties
  4. 4During the first incident, publish on the page, not only by email
  5. 5At audit time, hand over the link — the history is already there

Evidence no longer has to be collected before an audit: it collects itself.

Frequently asked questions

Is a status page required for SOC 2?

No, the standard names no tool. But a public page with history is the fastest way to show you communicate with external parties.

How long is history kept?

Reports stay for as long as the page exists. Check data retention depends on the plan — from 14 days to 24 months.

Can I export the evidence?

Yes: API, CLI, RSS and JSON feeds. The page is also available as Markdown.

Let the evidence collect itself

Create a pageAll use cases