Third Party Index

Snapshot 20189

Document
Trust center
URL
https://trust.alguna.com/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
81848 bytes
SHA-256 (raw)
674b8e90243348a829116d30bd9f5b721b757a955aa6c2f62346aa017e3e9e95
SHA-256 (normalized text)
022e2dfa8e4969c164bc932d099f9a9acdb3247952ffc14da5ceffc293f43fb8

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Monitored and Powered by
Trust Center
alguna.com
[email protected]
Compliance overview
Current compliance status across frameworks
SOC 2 Type 2
Compliant
Compliance Program
An overview of security controls in place
Access Control and Authorization
Access granting process used
Access requests to sensitive data required
Access requests to sensitive infrastructure required
Access revoking process enforced
Account inventory maintained
Dormant accounts disabled
MFA required for administrative access
MFA required for infrastructure access
Password management policy enforced
Data Management and Protection
Data encrypted at rest
Data encrypted in-transit
Data inventory maintained
Data labeled by sensitivity level
Data management and retention policy established
Disaster Recovery
Automated backups enabled
Business continuity and disaster recovery policy established
Data recovery process established
Disaster recovery plans tested
Recovery data isolated
Email Security
DMARC policy and verification used
Email account access restricted
Email settings block malicious content
Endpoint Security
Anti-malware deployed on end-user devices
Data encrypted on end-user devices
Firewall maintained on end-user devices
Mobile device management (MDM) used
Unauthorized software on end-user devices addressed and removed
Infrastructure Security
Active discovery tools used
Buckets not exposed publicly
Configuration management system established
Firewall restricts public access to infrastructure
Infrastructure changes logged
Infrastructure changes require review
Infrastructure deployed using an infrastructure-as-code tool
Unauthorized assets addressed and removed
Unique production database authentication enforced
Web Application Firewall (WAF) used
Monitoring and Incident Response
Adequate audit log storage maintained
Audit log management process maintained
Audit logs collected
Incident response policy established
Infrastructure performance monitored
Log management used
Network infrastructure monitored
Organizational Security
Asset inventory maintained
Asset management policy acknowledged by employees
Code of conduct acknowledged by contractors
Code of conduct acknowledged by employees
Code of conduct enforced
Company security commitments externally communicated
Confidentiality Agreement acknowledged by contractors
Confidentiality Agreement acknowledged by employees
External support resources available (i.e., documentation)
Offboarding process established
Onboarding process established
Performance evaluations conducted
Reference calls performed for employees
Roles and responsibilities specified
Security awareness training conducted
Service description communicated
Software development lifecycle established
System changes externally communicated
System changes internally communicated
Vendor agreements established
Whistleblower policy established
Risk Management
Cybersecurity insurance maintained
Risk assessments performed
Risk management policy established
Vendor inventory maintained
Vendor management program established
Vendors classified by data sensitivity
Vendors classified by risk level
Vulnerability Management
Automated software patch management performed
Penetration testing performed within the last 12 months
Vulnerabilities scanned
Vulnerability management policy acknowledged by employees