SOC 2 does not require a particular code review tool. The AICPA's Trust Services Criteria are used for evaluation regardless of the specific controls an organization implements.[1] The criterion that covers code changes is CC8.1: “The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives.”[1]
A common way to meet it is the pull request itself: every change goes through a pull request, a required reviewer approves it, CI tests it, and the merge ties the change to what was deployed. That record is the evidence an auditor can sample — so the review has to happen on every change, and it has to leave a trace.
IonWarp adds an automated reviewer to that record. On every pull request, SOC 2 Review looks for control gaps the change introduces — a privileged action with no audit record, an audit entry removed, a required CI gate or CODEOWNERS rule disabled, secrets or PII written to logs or responses, encryption turned off — and names the Trust Services criterion each finding breaks. Security Review runs alongside it, and the findings, the fixes and your team's approval stay on the pull request.
To be clear about what this is: IonWarp produces review evidence. It does not make you SOC 2 compliant, it does not replace the human approval your controls require, and your auditor decides which evidence satisfies your controls.