Loxeai
Built a verifiable, open-source SoC 2 readiness scanner
Last verified:
What is Loxeai?
LoxeAI is an AWS‑native SOC 2 evidence‑collection and readiness tool that scans your AWS environment and produces a verifiable evidence package for your SOC 2 audit. It connects to your account via a read‑only IAM role, then queries multiple AWS services (IAM, S3, CloudTrail, Config, GuardDuty, SecurityHub, KMS, Lambda, RDS, SNS, CloudWatch, EC2, WAF, etc.) to collect configuration metadata and map findings to 12 critical SOC 2 controls.
A key feature is that every finding is tied to the exact AWS API call used, including the endpoint, timestamp, and a SHA‑256 hash of the raw response, so auditors can independently re‑run and confirm the evidence. This reduces manual evidence gathering, version confusion, and screenshots scattered across folders, while giving you a single, tamper‑evident package that aligns with common trust‑service criteria.
LoxeAI is primarily aimed at AWS‑native SaaS and fintech companies that need to be SOC 2 Type 1 or Type 2 ready but want to avoid lengthy, expensive third‑party tools. It serves founders, CTOs, and security leads who want fast gap reports, a clear remediation roadmap, and an intelligent copilot (called Gideon) that suggests fixes, generates policies, and helps prepare for audit questions.
Beyond the scanner, LoxeAI includes a compliance copilot that interprets your scan results and guides you through prioritized remediation steps, risk‑register creation, and answer rehearsal for auditors. The tool is designed to be lightweight: one‑time per‑scan pricing, no mandatory dashboard, and an opt‑in, privacy‑first model where you can delete all scan data at any time, making it attractive for lean, pre‑series‑A or early‑stage teams that value speed, transparency, and cost control.
Loxeai pricing
Pricing model: Freemium
LoxeAI offers a free plan with a free scan and a basic gap report that includes gap score, evidence count, and top findings but leaves some detail locked. The paid offering is a one‑time, per‑report fee of 99.00 USD per scan, with no subscription or monthly billing. The paid tier includes deep analysis across 12 critical SOC 2 controls, traceable evidence, remediation CLI commands, the Gideon compliance copilot, scan history and deltas, and the ability to edit and resolve findings in the report.
Loxeai pros
- Produces verifiable SOC 2 evidence tied to exact AWS API calls
- Includes SHA‑256 hashes for raw API responses so auditors can re‑run them
- Fast scan setup: provision read‑only IAM role, paste ARN, get a gap report in under 30 seconds
- One‑time per‑report fee instead of recurring monthly subscriptions
- No credit card required for the free scan and basic gap report
- Free tier includes gap score, evidence count, and top‑level findings
- Deep analysis across 12 critical SOC 2 controls in a single scan
- Provides traceable evidence for each finding, not just screenshots
- Remediation roadmap with copy‑paste AWS CLI commands for fixes
- Gideon compliance copilot that tailors advice to your specific scan results
- Generates security policies, incident‑response plans, and change‑management templates
- Maintains a risk register aligned with AICPA taxonomy using an 8‑question intake
- Auditor‑rehearsal feature to practice answers before your actual audit
- Read‑only, ExternalId‑bound IAM role limits access and enhances security
- Zero secret material accessed; never reads Secrets Manager values or KMS‑encrypted payloads
- Data stored temporarily (30 days) and can be permanently deleted anytime
Loxeai cons
- Limited to AWS‑native environments; no coverage for non‑AWS infra or other clouds
- Scans only configuration metadata, not application or customer data, so it misses some contextual risk
- Only supports 3 scans per ExternalId per day, which may slow iterative testing
- One‑time per‑report pricing can add up if you need multiple frequent scans
- No built‑in continuous monitoring or long‑term historical dashboards like some competitors
- Evidence storage is short‑lived (30 days) unless you explicitly extend or download it
- Can only connect via AWS IAM role, which may complicate environments with complex identity architectures
- No persistent multi‑user dashboard or shared workspace, limiting collaboration
Frequently asked questions about Loxeai
What does LoxeAI actually scan in my AWS account?
LoxeAI scans configuration metadata from a defined set of AWS services, including IAM users, roles, policies, password policy, and MFA; S3 buckets for encryption, public access, and versioning; CloudTrail trails and event selectors; AWS Config recorders and rules; EC2 security groups, VPCs, and flow logs; KMS keys and rotation policies; GuardDuty detectors and finding statistics; SecurityHub standards and high/critical findings; SSO/Identity Center permission sets; Secrets Manager metadata (never values); WAF Web ACLs and protected resources; and Lambda, RDS, SNS, and CloudWatch configurations. It does not access application data, customer data, or secret values.
How does LoxeAI make evidence verifiable for auditors?
Each finding in LoxeAI is tied to the exact AWS API endpoint that produced it, along with a timestamp and a SHA‑256 hash of the raw API response. This allows your auditor to independently re‑run the same API call and compare the resulting hash to what is in the report, providing a tamper‑evident, third‑party‑verifiable evidence trail instead of relying on static screenshots or ad‑hoc documentation.
Is LoxeAI a subscription or pay‑per‑scan tool?
LoxeAI is pay‑per‑scan, not a subscription. The free plan lets you run scans and get a basic gap report without a credit card. If you need a full, auditor‑submittable report with detailed findings, remediation commands, and Gideon copilot features, you pay a one‑time fee of 99.00 USD per report, and there is no recurring monthly billing.
How long does LoxeAI keep my scan data?
Scan data is stored in LoxeAI’s Cloudflare Workers infrastructure for 30 days after report delivery. After that period the data is automatically deleted unless you request an extension. You can also permanently delete all scan data, reports, and account records at any time by request, and the system does not store AWS credentials or secret values.
Can LoxeAI integrate with my existing SOC 2 compliance tools?
LoxeAI is designed as a standalone evidence‑layer scanner that outputs a verifiable report and CLI‑ready remediation steps, rather than a full‑suite SOC 2 platform with integrations to other tools. You can manually feed its findings into other systems, but it does not currently offer built‑in API integrations or export connectors to popular SOC 2 vendors like Drata or Vanta.
What security and privacy controls does LoxeAI enforce?
LoxeAI uses a read‑only IAM role with ExternalId binding, so it cannot make changes to your AWS account and its access can be revoked at any time by you. The scanner only accesses configuration metadata and never reads secrets, credentials, or application/customer data. Evidence data is stored in Cloudflare D1 (a SQLite‑compatible edge database) and raw AWS API responses are kept for 30 days, after which they are deleted unless extended. You can request access, deletion, correction, or portability of your data on demand.
What is Gideon and how does it help with SOC 2?
Gideon is LoxeAI’s compliance copilot that interprets your scan findings and creates a remediation roadmap with ordered, copy‑paste AWS CLI commands tailored to your environment. It also generates security policies, incident‑response plans, and change‑management procedures, maintains an AICPA‑aligned risk register based on an 8‑question intake, and lets you rehearse answers to common auditor questions so you walk into the audit better prepared.
Does LoxeAI support multi‑account or multi‑region AWS environments?
LoxeAI is built for AWS‑native environments and can collect configuration metadata from multiple services across regions, but the primary workflow is scoped per AWS account and ARN. It currently operates on a per‑account read‑only role model, so you need to set up and run scans for each relevant account or organization unit separately rather than fully automated, cross‑account continuous monitoring.
Can I delete my data and stop using LoxeAI at any time?
Yes. You can permanently delete all scan data, reports, and account records at any time by request. You can also revoke the IAM role in your AWS account to immediately cut off access. LoxeAI does not persist access beyond the role you grant, and all evidence data is deleted after 30 days unless you explicitly extend that retention window.
Who is the main target audience for LoxeAI?
LoxeAI is primarily aimed at AWS‑native SaaS and fintech companies that need to be SOC 2 Type 1 or Type 2 ready without the overhead of expensive, complex third‑party platforms. It suits lean engineering teams, early‑stage startups, and compliance‑conscious founders or CTOs who want fast, transparent evidence collection, a clear remediation path, and a copilot that helps them answer auditors instead of relying on manual spreadsheets and screenshots.