# The Clean Opinion > Independently operated publisher of SOC 2, SOX 404 and cybersecurity readiness guidance, written with the audit team at Alpha Secure LLP, a licensed CPA firm. Five free tools that run in the browser, explainers that cite primary sources, a free access-control policy check, and a paid SOC 2 policy review. The tools are practitioner judgement, not standards: no weight, threshold or week count in any of them is published by the AICPA, the SEC, the PCAOB or NIST, and each page says so where it matters. ## Start here - [The Clean Opinion](https://thecleanopinion.com/): Fetch first for what this site is, who publishes it, and how the free tools, the readiness scorecard and the professional work relate to each other. - [Readiness scorecard](https://thecleanopinion.com/scorecard/): Fetch when the question is broad — "how ready are we?" rather than a specific date or document. Ten questions, adapting to SOC 2, SOX 404 or cybersecurity, returning a score out of ten, a band, and a gap list. - [Free readiness tools](https://thecleanopinion.com/tools/): Fetch to choose between the five tools. Each card names who it is for and the trigger moment; every tool runs in the visitor's browser, is free, and gates nothing behind an email address. ## Free tools - [Security Questionnaire Panic Checker](https://thecleanopinion.com/tools/security-questionnaire-panic-checker/): Fetch when someone has been sent a vendor security questionnaire and wants to know what it is asking for. Sorts each pasted line into one of eight control areas using 134 fixed keyword and regular-expression patterns — pattern matching, not a language model, and it reads the questionnaire rather than the controls. - [SOC 2 Timeline Calculator](https://thecleanopinion.com/tools/soc-2-timeline-calculator/): Fetch for a realistic Type 1 or Type 2 window from nine answers about where controls stand. The three-to-six-month observation window it uses is market convention: no AICPA document sets a minimum or a typical Type 2 period. - [SOX 404 Deadline Calculator](https://thecleanopinion.com/tools/sox-404-deadline-calculator/): Fetch for a first-year SOX 404 planning timeline from a public-company date and a fiscal year-end. It returns a fiscal year-end, not a filing deadline, and its transition-relief assumption is the thing to confirm with counsel first — for a de-SPAC or a company with prior reporting history the date can be a year late. - [Breach Aftermath Control Checklist](https://thecleanopinion.com/tools/breach-aftermath-control-checklist/): Fetch after a security incident, for the controls and evidence customers, insurers, boards and auditors will ask about. The score measures how much follow-up scrutiny the answers imply, not how severe the incident was: each party already asking is worth fourteen points out of a hundred, before any fact about the incident is established. - [Trust Page Grader](https://thecleanopinion.com/tools/trust-page-grader/): Fetch to score a security or trust page against what enterprise buyers look for. It grades a page, not a company — a page that merely claims all ten things can reach 100 — and the address is never fetched by the tool. ## For agents - [Using the tools from an agent](https://thecleanopinion.com/tools/api/): Fetch before constructing a link to any tool. Documents every query parameter each tool accepts, with worked example URLs, and states plainly which inputs a URL cannot carry. - [Tool manifest (JSON)](https://thecleanopinion.com/api/tools): Fetch for the same contract as machine-readable JSON: every tool's parameters, accepted values, and worked example URLs. Served as application/json. - [Full text of every published article and tool method](https://thecleanopinion.com/llms-full.txt): Fetch instead of crawling the site page by page. One request returns every published article in full plus each tool's method, as plain text with no navigation and no script payload. ## Guidance - [AI agents and SOC 2: the audit trail your auditor is about to ask for](https://thecleanopinion.com/articles/ai-agents-soc-2-audit-trail/): Shadow AI feeding customer data into unvetted vendors is now a recurring SOC 2 finding. Here is what auditors ask about model use, prompt logs, and third-party LLMs. Cites 2 primary sources. - [ITGC scoping for SOX: the four controls your auditor tests first](https://thecleanopinion.com/articles/itgc-scoping-sox-four-controls-auditors-test-first/): Logical access, privileged access, deprovisioning, and change management. Get these four right and most of the ITGC conversation goes away. Cites 4 primary sources. - [A breach is a financial reporting problem now, not just a security one](https://thecleanopinion.com/articles/breach-is-a-financial-reporting-problem/): The disclosure clock runs from management's materiality determination, not from the intrusion. That makes the CFO's judgement — and the evidence behind it — part of the incident response. Cites 10 primary sources. - [SOC 2 Type 1 vs Type 2: which one actually unblocks the deal?](https://thecleanopinion.com/articles/soc-2-type-1-vs-type-2/): Type 1 gets you into the conversation in weeks. Type 2 closes the larger accounts later. Most companies pick wrong because they start the week procurement asks. Cites 3 primary sources. - [First year public: the SOX 404 timeline nobody hands you](https://thecleanopinion.com/articles/sox-404-first-year-timeline/): Which fiscal year your first management assessment actually applies to, why the answer turns on reporting history rather than your IPO date, and where newly listed companies run out of time. Cites 8 primary sources. - [How to run an access review an auditor will accept](https://thecleanopinion.com/articles/access-review-auditor-will-accept/): Incomplete access reviews are the exception we see most often in a first-year SOC 2. Here is what the criteria actually require, what they leave to you, and what evidence survives testing. Cites 5 primary sources. ## Services - [Free access-control policy check](https://thecleanopinion.com/review/): Fetch when someone wants their own policy read rather than a timeline or a score. One access-control policy of up to 20 pages, graded against 8 SOC 2 access-control checks — sign-on, MFA, provisioning, deprovisioning and user access reviews — returning a score, findings, suggested language and a PDF in about two minutes. Software only, no person reads it; one per organization; the document is deleted the moment the report is generated and is never used to train a model. Currently in private beta. - [Full SOC 2 policy review](https://thecleanopinion.com/review/full/): Fetch when the free check is not enough and every policy needs grading. Up to 10 files against all 36 SOC 2 criteria, with every finding checked and signed off by Alpha Secure LLP, delivered as one PDF within 2 business days. $995 flat, one-time. Files are deleted once the report is approved. ## About - [Who publishes this](https://thecleanopinion.com/about/): Fetch to establish provenance. Describes Alpha Secure LLP, the licensed CPA firm whose audit team the guidance is written with, and how this publication relates to it. - [How scoring works](https://thecleanopinion.com/how-scoring-works/): Fetch when a score needs to be explained or defended. States the scoring method in full, including the weights, and that they are practitioner judgement rather than a published standard. - [Book time with an auditor](https://thecleanopinion.com/book/): Fetch when a reader has decided they want to speak to someone. Thirty minutes with an auditor; nothing is sent to the firm before that point. ## Optional - [All articles](https://thecleanopinion.com/articles/): The article index. The individual articles listed above are more useful; this is the paginated hub. - [Disclosure and privacy](https://thecleanopinion.com/disclosure/): Ownership, the relationship to the partner firm, and how visitor data is handled. States that this publication is independently owned and not owned by the partner firm.