Catalogue › Security & identity › AuditPoppy
AuditPoppy
SOC 2 audit-readiness in your own cloud
Download AgentsPoppy to get AuditPoppy
The AgentsPoppy app is free, and runs on macOS, Windows and Linux. AuditPoppy installs from inside it — the app asks your permission, shows exactly what will be created in your cloud, and can remove all of it later.
Screenshots
About AuditPoppy
Get ready for your SOC 2 audit without shipping your infrastructure's secrets to anyone. AuditPoppy runs inside your own cloud account. It turns on the checking services your provider already offers (AWS Config and AWS Security Hub), reads what they find, and maps every result to the Trust Services Criteria an auditor actually asks about — so you get a gap report that names the control, the affected resources, and what to do about it. It then keeps collecting. A small scheduled function writes a dated, immutable evidence bundle into a locked-down bucket in your account every month, because an auditor needs proof your controls operated over the audit period, not just today. It writes the policies too — access control, change management, incident response, vendor management, data retention — pre-filled from what it can actually observe in your account, with your own answers kept visibly separate from the facts it read. When you are ready, one button builds the auditor package: the gap report, the policies, the evidence index and your notes, as a PDF and as JSON. The evidence never leaves your cloud. The developer receives none of it. And when you remove AuditPoppy it takes everything it created with it — the stack, the bucket, the schedule — and leaves what was already there exactly as it was.
What you get
Included, free
- ✓Gap report against the Trust Services CriteriaTurns on the checking services your cloud already offers (AWS Config, AWS Security Hub), reads every finding, and maps it to the criteria an auditor asks about — naming the control, the affected resources and what to do.
- ✓Evidence collected every month, automaticallyA scheduled function writes a dated, immutable bundle into a locked-down bucket in your account. An auditor needs proof your controls operated across the period, not a screenshot from today.
- ✓Policy pack, pre-filled from what is actually thereAccess control, change management, incident response, vendor management, data retention — pre-filled from your observed posture, with your own answers kept visibly separate from the facts it read.
- ✓The auditor package, in one clickGap report, policies, evidence index and your notes, as a PDF and as JSON. On the personal tier the PDF carries a watermark.
- ✓What it will cost, before you switch anything onA live-priced forecast for your own account, read from your provider's price list — because the continuous change recording that an audit requires is the real cost, and you should see it first.
- ✓Removes itself completelyOne button takes away everything it created — the stack, the bucket, the schedule, the roles — and leaves what was already there untouched. Verified against a real account, not asserted.
Paid features
- ★Clean exports for companies of ten or moreThe same package without the watermark, under a licence tied to the cloud account being audited rather than to whoever paid — so it survives a reinstall or a new machine. Free for companies under ten people.
Pricing
Prices are read live from the developer's own listing. Whatever this poppy costs, the cloud resources it creates are billed by AWS directly to you — AgentsPoppy never marks them up. Paid features are bought inside the app; the developer is the merchant of record.
Data & privacy
Nothing leaves your cloud. The developer declared that no data this poppy handles is ever sent outside the AWS account it runs in. You can verify that claim yourself — the source is public.
Developer & support
| Developer | Olly Digital |
|---|---|
| Website | https://agentspoppy.com/poppies/auditpoppy |
| Source code | https://github.com/leonct74/audit-poppyPublic by requirement — you or your AI can audit exactly what it does before installing. |
| Support | support@agentspoppy.com https://github.com/leonct74/audit-poppy/issues |
| Age rating | Everyone |
| Runs on | macOS, Windows and LinuxNeeds AgentsPoppy 0.3.20 or newer. |
| Where it runs | Your own AWS account.AgentsPoppy holds no copy of your data and cannot read it. Cloud usage is billed to you by AWS at their prices. |
Support for the poppy itself comes from its developer. For the AgentsPoppy app, see Security or our terms.
Ready to run AuditPoppy in your own cloud?
Download the free AgentsPoppy app for macOS, Windows or Linux, connect your AWS account once, and install AuditPoppy from the catalogue inside it.