First SOC 2 program
A credible starting point
Place production secrets in a managed secrets service, stop committing credentials to source control or build settings, assign an owner to every machine identity, separate credentials by service and environment, and scan repositories for exposed values.