Snapshot 21620
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Monitored and Powered by circleback.ai [email protected] Compliance overview Current compliance status across frameworks SOC 2 Type 2 Compliant HIPAA Compliant EU-U.S. Data Privacy Framework Compliant GDPR Compliant Featured documents Key security and compliance documentation Circleback - SOC 2 Type II Report - May'25 to July'25 Request access Subprocessors Request access Q3 2026 Circleback Pentest Request access View all documents Compliance Program An overview of security controls in place Access Control and Authorization Access management policy established Employee access regularly reviewed MFA required for critical services Password management policy enforced Password management policy established Data Management and Protection Consent for collecting and managing data obtained Data encrypted at rest Data inventory maintained Data management and retention policy established Data transfer mechanisms established External privacy inquiries managed Privacy disclosure and notification mechanisms established Privacy policy created and maintained Disaster Recovery Automated backups enabled Business continuity and disaster recovery policy established Data recovery process established Disaster recovery plans tested Recovery data isolated Email Security DMARC policy and verification used Email account access restricted Email settings block malicious content Endpoint Security Anti-malware deployed on end-user devices Data encrypted on end-user devices Firewall maintained on end-user devices Infrastructure Security Active discovery tools used Buckets not exposed publicly Configuration management system established Firewall restricts public access to infrastructure Infrastructure changes logged Infrastructure changes require review Network infrastructure continuously updated Unauthorized assets addressed and removed Unique production database authentication enforced Web Application Firewall (WAF) used Monitoring and Incident Response Adequate audit log storage maintained Audit log management process maintained Audit logs collected Breach notification process established Incident response exercises performed Incident response policy established Incident review process implemented Infrastructure performance monitored Log management used Network infrastructure monitored Organizational Security Acceptable use policy established Asset inventory maintained Asset management policy established Code of conduct established Company security commitments externally communicated Confidentiality Agreement acknowledged by contractors Confidentiality Agreement acknowledged by employees External support resources available (i.e., documentation) Internal privacy policies established Internal security audit performed Offboarding process established Onboarding process established Password manager used Performance evaluations conducted Physical access restricted Physical security policy established Reference checks performed for employees Relevant authorities identified Roles and responsibilities specified Sanction policy established Security awareness training conducted Security official assigned Service description communicated Software development lifecycle established System changes externally communicated System changes internally communicated Vendor agreements established Workstation use and security policy established Risk Management Risk assessments performed Risk management policy established Vendor management program established Vulnerability Management Automated software patch management performed Penetration testing findings remediated Penetration testing performed within the last 12 months Vulnerability management policy established