First SOC 2 program
A credible starting point
Use one controlled document repository, name an owner and approver on every policy, and maintain a simple review calendar. The founder or security lead should approve changes in writing and keep prior versions rather than replacing them without history.