Sitewrap Edge After the snapshot
How Sitewrap helps SOC 2 website controls
Wrap the existing CMS with an edge control plane — firewall, headers, consent, admin gating, and an audit trail — without rebuilding the site.
Edge firewall before origin Rate limits, 404 bans, probe blocks, and allowlists so scanners die at Sitewrap instead of waking the CMS.
Headers that survive cache HIT HSTS, nosniff, Referrer-Policy, Permissions-Policy, and CSP on the responses buyers actually receive.
Consent-aware analytics Masked IPs, CMP, Mixpanel/GA4 gated on consent — the story InfoSec expects on a marketing domain.
Admin gating Keep login and CMS admin off the public internet until Sitewrap unlocks them.
Audit trail & MFA Who changed firewall, deploys, and tracking. TOTP for dashboard operators. Backup evidence on the Compliance tab.
A dashboard score that matches the scan The same TSC-style control list your team already uses internally — now with a public snapshot for any domain.