How does policy controls on fine-tuning data satisfy SOC 2 requirements?

Kastra enforces policy controls on fine-tuning data at the moment of execution and writes a signed evidence record for every training record. Auditors get a complete, append-only trail of who attempted what, what policy fired, why the decision was made, and what data was touched. This evidence maps directly to SOC 2, PCI DSS, SOX, FINRA, MiFID II control families.