United States · AICPA · Trust Services Criteria

SOC 2: the change criterion (CC8.1) meets AI-written code

CC8.1 asks that infrastructure and software changes be authorized, designed, tested and approved before deployment. Your SOC 2 auditor samples changes and asks for evidence of each step; an AI generating most new code makes that evidence blurry.

SOC 2 · Common Criteria CC8.1 (change management)

Changes must be authorized and approved prior to implementation, with evidence of who did so.

What the regulation demands of software development

  • CC8.1. Documented authorization and approval of every change before production.
  • CC7.1. Vulnerability detection and management.
  • CC6.8. Controls over unauthorized software.
  • Evidence. The auditor samples changes from the period: each one needs its record.

How LineBreak answers

  • Nothing reaches production with known vulnerabilities. Every change is scanned before merging; if the scanner cannot run, the change does not pass. Exceptions are human, scoped to one exact finding, with name and reason on the record.
  • The AI writes the code; an identified person signs. Approved criteria carry the name of who approved them. The AI writing code can read them, but cannot modify them.
  • Every approval is cryptographically signed. Your auditor verifies it independently, without relying on us or on the team's word, years later if needed.
  • The evidence lives in YOUR infrastructure. Not on our servers. The record of every change (who approved what, when, with what result) travels with the code itself.

What LineBreak is NOT

  • LineBreak does not certify or guarantee compliance with any regulation: it produces the evidence your accountable people answer with.
  • It does not replace the roles your regulation requires (security officers, internal audit, regulatory reporting).
  • Decisions and accountability remain human. That is the product's design principle.

An AI-generated change is blocked, a person approves it by name, and the audit report is generated in front of you. With your risk team or your auditor present.