Snapshot 19717
Normalized text
Scripts and page chrome removed; this is what change detection compares.
FundApps is continuously monitoring its overall security posture. Compliance Documentation of our compliance against global standards including certifications, attestations, and audit reports. Security Continuous monitoring Note: If a control is passing all tests, it will be marked as green. If a control has a failed test that was not resolved within the past 3 days, it will be marked yellow. Data Security Data Backups Encryption at Rest Encryption in Transit Least-Privileged Policy for Sensitive Data Access Infrastructure Security Access to Remote Server Administration Ports Restricted Change Review Process Log Management System Logging/Monitoring Monitoring Processing Capacity and Usage Network Security Controls Root Infrastructure Account Monitored Organization Security Access Deprovisioning Defined Management Roles & Responsibilities Formal Screening Process Job Descriptions Multi-Factor Authentication On-Call Team Subprocessors Shortcut Ticketing software Data location: USA Slack Communication/messaging tool Data location: USA FundApps The FundApps group is formed of 3 separate entities located in the UK (FundApps Ltd), Singapore (FundApps Pte Ltd) and USA (FundApps Inc) and each will contribute to the provisio... Data location: United States ON24 Webcasting and virtual event technology used to host webinars and other interactive demonstrations. Data location: Xero Accounting software for processing invoices and payments from clients and suppliers. Data location: Slack Communication/messaging tool Data location: Topics and common questions 21 FundApps maintains a robust security and compliance posture validated through independent third-party audits. We hold ISO 27001 Certification and undergo annual SOC 2 Type 2 assessments. Our infrastructure is hosted entirely within the EU on Amazon Web Services, which holds industry-standard certifications including ISO 9001, ISO 27001, and SOC 1 and 2 certifications. We are committed to aligning our processes with ISO 27001 and the NIST Cyber Security Framework. We maintain a comprehensive, uniform set of policies and procedures that apply consistently across all clients. This standardised approach ensures operational sustainability, compliance consistency, and reduces the risk of inconsistent security posture across our client base. Our policies are documented, regularly reviewed, and updated to reflect evolving regulatory requirements and industry best practices. To support efficient and accurate security assessments, we provide clients with access to our trust portal, which contains our SOC 2 Type 2 Report, ISO 27001 Certification, and our policy portal, which all of our security documentation. We encourage clients to self-serve from these resources, as this approach minimises operational complexity and reduces the risk of human error inherent in manual questionnaire completion. Manual Due Diligence Questionnaire processes create significant operational burden and increase the likelihood of transcription errors, inconsistencies, and outdated information. By providing comprehensive, audited documentation through our trust portal, we enable clients to conduct thorough security assessments whilst maintaining the integrity and accuracy of our security posture. FundApps is assessed annually by independent third-party auditors which provides FundApps with: a SOC 2 Type 2 Report; and an ISO 27001 Certification. Both documents can be requested from FundApps' Trust Center (section Compliance). FundApps platform is hosted in Amazon Web Services datacentres located in Dublin, Ireland and Frankfurt, Germany. FundApps' security posture is designed to address the challenges created by models such as Anthropic's Mythos.This includes, but is not limited to, the following controls: A. Multiple avenues to detect vulnerabilities affecting our platform: - Static Application Security Testing (SAST) on every code change. - Weekly Dynamic Application Security Testing (DAST) of the application. - Bug-bounty program on a reputable platform. - Annual penetration tests performed by a CREST-accredited third-party. B. Short SLA's to remediate or mitigate vulnerabilities, prioritised by severity, exploitability and internet exposure, as detailed in our vulnerability management policy (cf. the vulnerability management policy in our policy portal), which is audited and evidenced in our SOC 2 report. - Critical: ≤2 working days - High: ≤5 working days - Medium and - Low: ≤20 working days D. A Web Application Firewall to stop incoming malicious traffic, and the ability to apply virtual patching. E. A SIEM that centralises all security events from our systems operated by our 24/7 SOC. F. A robust security incident management process which defines how incidents are triaged, contained, assessed, remediated and learned from, as detailed in our security incident response policy (cf. the security incident policy on our policy portal). Each of these controls is audited and described in our SOC 2 Type 2 Report available in this trust portal. We now offer Just-In-Time access, a new access control that allows clients to provide FundApps staff with access to their environment for a set period based on the specific context (e.g., incident resolution, investigations). In other words, FundApps staff do not have access to client data unless clients provide it. You can read more about Just-In-Time access here: https://support.fundapps.co/hc/en-us/articles/20198833113885-Just-In-Time-JIT-Access-Management Additional details If you're a SteelEye client, please also visit: https://trust.steel-eye.com Privacy details Privacy URL