Snapshot 17275
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Monitored and Powered by Trust Center Comma Compliance captures and archives business communications across WhatsApp, Signal, iMessage, and 70+ channels to meet SEC, FINRA, and global requirements for regulated industries. Our Trust Center gives you everything you need to evaluate how Comma protects, manages, and archives your data. commacompliance.com status.commacompliance.com security@commacompliance.com Compliance overview Current compliance status across frameworks SOC 2 In progress ISO 27001 In progress Featured documents Key security and compliance documentation Information Security Policy Request access Encryption and Key Management Policy Request access Network Security Policy Request access View all documents Compliance Program An overview of security controls in place Access Control and Authorization Access granting process used Access management policy established Access requests to sensitive data required Access requests to sensitive infrastructure required Access revoking process enforced Account inventory maintained Dedicated administrator accounts used Dormant accounts disabled Employee access regularly reviewed MFA required for administrative access MFA required for critical services MFA required for infrastructure access Password management policy enforced Password management policy established Data Management and Protection Data deletion enforced Data encrypted in-transit Data inventory maintained Data is encrypted at rest using customer-controlled keys Data labeled according to classification level Data management and retention policy established Data masking procedures used Key management process implemented Disaster Recovery Automated backups enabled Business continuity and disaster recovery policy established Business continuity plans documented Business impact analysis performed Data backup and recovery policy established Data recovery process established Data recovery tested Disaster recovery plans tested Recovery data isolated Email Security DMARC policy and verification used Email account access restricted Email settings block malicious content Endpoint Security Anti-malware deployed on end-user devices Automatic session locking enforced Data encrypted on end-user devices Firewall maintained on end-user devices Software inventory on end-user devices maintained Infrastructure Security Active discovery tools used Administrator access restricted Anti-malware deployed on infrastructure Automated security scanning performed on infrastructure Buckets not exposed publicly Clock synchronization enforced Cloud infrastructure used Configuration management system established Firewall restricts public access to infrastructure High availability infrastructure used Infrastructure changes require review Infrastructure deployed using an infrastructure-as-code tool Key management policy established Network security policy established Production and test environments separated Production deployment access restricted Pull requests used Unauthorized assets addressed and removed Unique production database authentication enforced VPN used Web Application Firewall (WAF) used Monitoring and Incident Response Audit log management process maintained Audit logs collected Compliance monitoring processes defined and implemented Incident response policy established Infrastructure performance monitored Log management used Logging and monitoring policy established Network infrastructure monitored Threat intelligence established Organizational Security Acceptable use policy established Asset inventory maintained Asset management policy established Change management policy established Code of conduct established Communication procedure established Company security commitments externally communicated Data-flow diagrams maintained Documentation procedure established Employment contracts used Human resource security policy established Information security communities identified Information security in project management integrated Information security policy established Internal security communication maintained Leadership security commitment established Management review implemented Network diagrams maintained Non-conformance and corrective action procedures established Offboarding process established Onboarding process established Operational procedures maintained Password manager used Performance evaluations conducted Physical access restricted Physical security policy established Policies signed by relevant personnel Reference checks performed for employees Relevant authorities identified Remote work policy established Resources for ISMS available Roles and responsibilities specified Scope for compliance framework established Security awareness training conducted Security official assigned Service description communicated Software development lifecycle established Statement of applicability completed System changes externally communicated System changes internally communicated Third-party security oversight conducted Vendor agreements established Risk Management Compliance policy established Internal audit program defined Outsourced development secured Risk assessments performed Risk management policy established Risk owners identified Risk treatment plans established Software supply chain risks monitored Vendor inventory maintained Vendor management policy established Vendor management program established Vulnerability Management Penetration testing findings remediated Penetration testing performed within the last 12 months Vulnerabilities scanned Vulnerability management policy established