Snapshot 18486
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Monitored and Powered by Trust Center quickture.com [email protected] Compliance overview Current compliance status across frameworks SOC 2 Type 2 Compliant GDPR Compliant Trusted Partner Network Compliant HIPAA Compliant EU-U.S. Data Privacy Framework Compliant Featured documents Key security and compliance documentation 2025-05 Quickture SOC 2 Type 2 Report Request access Q2 2026 Quickture Pentest Request access Quickture Subprocessors Report Request access View all documents Compliance Program An overview of security controls in place Access Control and Authorization Access granting process used Access management policy established Access requests to sensitive data required Access requests to sensitive infrastructure required Access revoking process enforced Account inventory maintained Dedicated administrator accounts used Dormant accounts disabled Employee access regularly reviewed MFA required for administrative access MFA required for applications MFA required for critical services MFA required for infrastructure access Password management policy enforced Password management policy established Data Management and Protection Consent for collecting and managing data obtained Data encrypted at rest Data encrypted in-transit Data inventory maintained Data labeled according to classification level Data management and retention policy established Data masking procedures used Data processing integrity and output validated Data transfer mechanisms established External privacy inquiries managed Privacy disclosure and notification mechanisms established Privacy policy created and maintained Disaster Recovery Automated backups enabled Business continuity and disaster recovery policy established Data backup and recovery policy established Data recovery process established Disaster recovery plans tested Recovery data isolated Email Security DMARC policy and verification used Email account access restricted Email settings block malicious content Endpoint Security Anti-malware deployed on end-user devices Automatic session locking enforced Data encrypted on end-user devices Firewall maintained on end-user devices Mobile device management (MDM) used Unauthorized software on end-user devices addressed and removed Infrastructure Security Active discovery tools used Anti-malware deployed on infrastructure Automated security scanning performed on infrastructure Buckets not exposed publicly Clock synchronization enforced Configuration management system established Firewall restricts public access to infrastructure High availability infrastructure used Infrastructure changes logged Infrastructure changes require review Infrastructure deployed using an infrastructure-as-code tool Key management policy established Network infrastructure continuously updated Production and test environments separated Production deployment access restricted Unauthorized assets addressed and removed Unique production database authentication enforced VPN used Web Application Firewall (WAF) used Monitoring and Incident Response Adequate audit log storage maintained Audit log management process maintained Audit logs collected Breach notification process established Incident response exercises performed Incident response policy established Infrastructure performance monitored Log management used Logging and monitoring policy established Network infrastructure monitored Organizational Security Acceptable use policy established Asset inventory maintained Asset management policy established Change management policy established Code of conduct acknowledged by contractors Code of conduct acknowledged by employees Code of conduct established Communication procedure established Company security commitments externally communicated Confidentiality Agreement acknowledged by employees Contact with authorities established Data-flow diagrams maintained Documentation procedure established Employee background checks performed External support resources available (i.e., documentation) Human resource security policy established Information security communities identified Information security policy established Information security program established Internal documentation maintained Internal privacy policies established Internal security audit performed Network diagrams maintained Offboarding process established Onboarding process established Performance evaluations conducted Physical access restricted Physical security policy established Policies signed by relevant personnel Policy for compelled disclosure from law enforcement established Remote work policy established Roles and responsibilities specified Sanction policy established Scope for compliance framework established Security awareness training conducted Security official assigned Service description communicated Software development lifecycle established System changes externally communicated System changes internally communicated Vendor agreements established Workstation use and security policy established Risk Management Data Protection Impact Assessment (DPIA) completed Risk assessments performed Risk management policy established Software supply chain risks monitored Vendor inventory maintained Vendor management policy established Vendor management program established Vendors classified by data sensitivity Vendors classified by risk level Vulnerability Management Automated software patch management performed Penetration testing findings remediated Penetration testing performed within the last 12 months Vulnerabilities scanned Vulnerability management policy acknowledged by employees Vulnerability management policy established