Illustrative ZK disclosure scenario · Not a SOC 2 certification

Operational controls, proven without the working papers

An illustrative ZK control-attestation proof lets a service provider or control owner prove a bounded privileged-access review without disclosing internal system topology, identities, raw logs, tickets, or sensitive audit evidence to a customer or auditor.

Scope note: Illustrative scenario only. It shows a possible proof shape for partner discussion; it is not a SOC 2 certification, legal advice, or a compliance determination.

Privileged-access review, proven inside the control boundary

The service provider or control owner holds the IdP access logs, review tickets, system inventory, and remediation evidence as the private witness. The proof carries only the public facts a customer or auditor needs to verify that the control was performed for a bounded audit window.

Service provider / control owner

The control owner binds the privileged-access review and remediation outcome locally before producing the proof.

IdP access logs + review tickets + system inventory + remediation evidence

Internal system topology, administrator identities, raw IdP logs, review tickets, system inventory, sampling details, and remediation evidence stay inside the issuer boundary; no sensitive audit evidence enters the proof envelope.

control_attestation = valid

privileged_access_review · cc6.1_admin_access_review

Expiry-bound, revocable control-attestation proof envelope
policy = Published SOC 2 control-attestation policy
policy_hash = 0x4b82…7e19
claim_type control_attestation
claim_purpose privileged_access_review
criteria SOC 2 Trust Services Criteria
control_id CC6.1
audit_window bounded review period
remediation_sla met
policy_hash 0x4b82…7e19
expiry bounded validity window
revocation_state unrevoked / re-checkable
proof_validity true

Customer / auditor

valid = true · policy_hash matched · disclosure_boundary = sealed

The customer or auditor re-checks the proof against the published control policy hash, the bounded audit window, and the current revocation state. The issuer’s operational witness is never returned with the decision.

Bind locally. Verify remotely.

The service provider or control owner seals internal system topology, administrator identities, raw IdP access logs, review tickets, system inventory, sampling details, and remediation evidence inside its boundary. It sends the customer or auditor only the proof and the minimum public claim fields needed to verify that privileged access was reviewed and remediation met the published SLA during the bounded audit window.

Wire shape proof + minimum public claim fields

The verifier gets a control decision, not the working papers.

Scoped, policy-bound control outputs

The customer or auditor learns that a control_attestation claim is valid for a privileged_access_review against the identified SOC 2 control and published policy hash, for the stated audit window, with the remediation SLA met and the proof still within its expiry and revocation rules. It can verify the scoped claim without receiving the witness.

No internal evidence crosses the partner boundary

Internal system topology, administrator identities, raw IdP access logs, review tickets, system inventory, sampling details, remediation evidence, and other sensitive working papers remain sealed inside the service provider or control owner boundary.

A ZK credential for a bounded control attestation.

ZK
control_attestation_v1

A zero-knowledge credential lets a service provider or control owner prove a scoped privileged-access control attestation against a published SOC 2 policy hash. The proof is revocable and re-checkable without turning the customer or auditor into a working-paper repository. See the PrivacyCore™ agent identity explainer for the underlying privacy-rail primitive, and read the FHE workflow for sensitive agent-side computation over regulated inputs.

Partner POC

Make the regulated claim verifiable, not visible.

Use the partner spec to map the issuer boundary, public policy fields, and verification flow for your own regulated workflow.

← Back to Regulated Verticals