SOC 2-ready security hardening (NDA)
- IAM rewritten to least privilege with credential rotation
- Secrets moved to Secrets Manager with Lambda rotation
- WAF and rate limiting in front of public endpoints
Controls in place and documented for the SOC 2 audit