Snapshot 35466
Normalized text
Scripts and page chrome removed; this is what change detection compares.
JedoxTrust Center jedox.com trust@jedox.com Overview Controls Security and compliance security rating 914 / 950 Industry Average 726 CSA STAR Level 1 CSA STAR Level 2 GDPR ISO 27001 ISO 27017 ISO 9001 NIS2 SOC 1 SOC 2 Type II About Jedox is the world’s most adaptable planning and performance management platform that empowers organizations to deliver plans that outperform expectations. Over 2,900 organizations in 140 countries trust Jedox to model any scenario, integrate data from any source and simplify cross-organizational plans across all business systems. With Jedox, you can react quickly to changes, plan for opportunities, and uncover what you didn’t know was possible. Controls See all 438 Security policies and procedures A formally defined information security program is documented, communicated & maintained. Information security program scope covers internal issues and external threats. Information security program resourcing is aligned to the organization's risk strategy, with adequate funding, staffing, and tools allocated. + 79 more Asset management Asset management program is approved by management and includes assigned ownership and responsibilities for maintaining, reviewing, and managing asset controls. Asset register is maintained. Acceptable use policy for information and associated assets has been developed, communicated and maintained effectively. + 78 more Infrastructure management Domain does not expire soon. Domain has not expired. Domain registrar or registry transfer protection enabled. + 88 more Data protection Periodic user access reviews are conducted. Unique IDs are required for authentication across systems and devices. User access rights are granted on a least-privilege basis, aligned with each role’s business needs. + 50 more Application security A secure development life cycle process is defined, implemented, and integrated into all development projects. Software development, testing, and staging environments are kept separate from the production environment. Security experts are engaged for development on all applications. + 40 more Risk management Formal risk assessment process is defined and implemented. Cybersecurity risk appetite and risk tolerance statements are formally documented, communicated to relevant stakeholders, and reviewed on a defined schedule. Information assets and business processes are inventoried and evaluated for risk exposure as part of the risk assessment process. + 27 more Operational resilience Scoped data backed up and stored offsite. Backup and related restoration procedures tested at least annually. Backup procedure in place for all information, software, and systems. + 55 more Resources Documents SOC2_Bridge Letter_Oct 2025_June 2026 Last updated Oct 1, 2026 PS880 Last updated Mar 9, 2026 26.1 Penetration Test Attestation Letter Last updated Feb 26, 2026 ISAE 3402 TYPE 2 REPORT Last updated Dec 25, 2025 SOC 2 TYPE 2 REPORT Last updated Dec 25, 2025 CSA STAR, CCM Version 4.0.5 Last updated Feb 6, 2026 Incident Management_V1.2_240430 Last updated Oct 7, 2025 ISO/IEC 27001:2024-01 Last updated Feb 6, 2026 ISO 9001:2015 Last updated Mar 6, 2025 Security policies and procedures Controls Information security program established Information security A formally defined information security program is documented, communicated & maintained. Published Oct 7, 2025 CSA STAR, CCM Version 4.0.5 SOC 2 TYPE 2 REPORT Information security program scope covers internal issues and external threats. Published Oct 7, 2025 CSA STAR, CCM Version 4.0.5 SOC 2 TYPE 2 REPORT ISO/IEC 27001:2024-01 Information security program resourcing is aligned to the organization's risk strategy, with adequate funding, staffing, and tools allocated. Published Oct 7, 2025 Information security governance program implemented Information security Information security policy is enforced by an appointed owner. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Executive leadership provides effective oversight and governance of the cybersecurity programme, fostering a risk-aware culture and driving continuous improvement. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information security and IT processes are retained in-house and/or outsourced with the same information security governance. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT All projects involving systems, applications, and platforms undergo an information security assessment. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information security strategy, policies and standards are reviewed on an annual basis and after major changes. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Compliance with information security policies is regularly and consistently monitored and managed. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Personnel have access to a clearly defined and confidential channel for promptly reporting suspected security events, policy violations, or observed weaknesses. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Policy objectives and requirements align with the strategic direction of the organization and are integrated into the organization's processes. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT A process is in place for identifying, correcting, and preventing recurrence of nonconformities in the information security program. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Deployed AI systems include defined human oversight roles for human-in-the-loop intervention and override of automated decisions when required. Published Oct 7, 2025 Risk management objectives are formally defined, approved by relevant stakeholders, and reviewed periodically. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Objectives and metrics are monitored to assess adherence to the information security policy and its effectiveness. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Management communicates and enforces the requirement that all personnel apply the organization’s security policies and procedures. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Compliance with information security policies is recorded and tracked in a risk register or equivalent system until resolved. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Reviews are conducted to ensure personnel, systems, and processes operate in compliance with applicable information security policies, standards, and procedures. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Critical dependencies are documented, prioritized based on impact, and communicated to relevant stakeholders. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Critical services relied on by external stakeholders are identified, documented and communicated appropriately. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Stakeholder groups relevant to cybersecurity risk management are identified, and their needs and expectations are documented and reviewed periodically. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information security-related legal, regulatory, statutory, and contractual obligations are identified, documented, and reviewed on a scheduled basis. Published Oct 7, 2025 Cybersecurity operations are continuously improved based on observations and lessons learned from the execution of routine processes, procedures, and team activities. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Risk assessment policies and procedures established Information security Documented risk assessment process for information security. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Responsibilities for assessing and accepting residual information security risks are defined and assigned. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information security risk assessment process address the risks to architecture, infrastructure, software, operations, business, cybersecurity, and IT services. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Risk assessment process includes evaluation of the potential consequences of identified risks and the likelihood of their recurrence. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Strategic cybersecurity opportunities are characterized and incorporated into risk management discussions and decision-making. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information security policy framework established Information security An information security policy is implemented and maintained with clearly defined and measurable objectives. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information security policies are based on accepted frameworks, and industry practices. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Topic-specific policies are defined and approved. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information security policies and procedures cover third-party risk management. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information security policies and standards are formally approved by senior management. Published Oct 7, 2025 Effective exceptions and exemptions process for information security policies, standards and procedures. Published Oct 7, 2025 Cybersecurity policies are periodically updated to reflect evolving threats, regulatory and technological changes, and strategic objectives, with updates communicated to all relevant stakeholders. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Acknowledgement of policies by new personnel before being granted access to the organization's information and assets. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Records and information handling program implemented Information security A documents and records-management programme is implemented and maintained. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Formal data governance program is implemented and maintained. Published Oct 7, 2025 Records are protected from unauthorized disclosure, misuse, loss, destruction, or alteration. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Safe practices for accessing, processing, storing or transmitting data on external systems. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT IT operations governance established IT operations management Documented and approved operating procedures for information processing facilities are maintained and made available to personnel responsible for their execution. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Operational IT responsibilities are formally defined. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Executive management ensures IT operations policies and procedures are aligned with the organization’s strategy and information security objectives. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT A defined process exists to conduct independent reviews of IT operations policies and procedures at least annually. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Incident Management_V1.2_240430 Operational change management program established IT operations management Documented operational change management policy approved by management, communicated to appropriate constituents, and assigned an owner. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT All operational changes require formal operational and security impact assessment and approval prior to implementation. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Operational change management policy defines categories of changes based on severity, risk, or business impact. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Operational change management policy includes procedures for addressing emergency changes. Published Oct 7, 2025 Operational change management policy includes multi-stakeholder review or a change advisory board. Published Oct 7, 2025 Operational change management policy includes testing and rollback plans for all high-impact changes. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Operational change management program implemented IT operations management Information security requirements are implemented when new systems are introduced, upgraded, or enhanced. Published Oct 7, 2025 Security requirements for new, upgraded, or enhanced systems are defined based on data classification and are integrated into project planning and delivery. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information security specifications for new, upgraded, or enhanced systems are developed using requirements from policies and regulations. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Business continuity requirements are considered for new, upgraded, or enhanced systems. Published Oct 7, 2025 Implementation of new and upgraded systems follows defined change management procedures. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Testing is required for validation of all controls required for new, upgraded, or enhanced systems. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT All changes are documented and reviewed after implementation for appropriateness and security impact. Published Oct 7, 2025 Installation of software on operational systems is restricted to authorized personnel. Published Oct 7, 2025 Independent security assessments undertaken Compliance management Industry recognized third-party information security certifications held. Published Oct 7, 2025 CSA STAR, CCM Version 4.0.5 SOC 2 TYPE 2 REPORT ISO/IEC 27001:2024-01 Responsibility for planning, coordinating, and responding to independent security assessments is formally defined and assigned. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Results of independent assessments are reviewed by management and used to improve. Published Oct 7, 2025 Internal audits of the information security program are conducted at planned intervals, in addition to external reviews. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Intellectual property and licensing Compliance management Topic-specific policies define acceptable use and protection of intellectual property, including software, documents, media, and trademarks. Published Oct 7, 2025 Only licensed or authorized software and content are permitted; ownership records and usage compliance are reviewed periodically. Published Oct 7, 2025 Human resources policy established Human resources security Documented human-resources security policy and procedures are formally approved, maintained, and communicated to all relevant personnel. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Human resources security policy effectiveness is reviewed at least annually using HR metrics and audit findings. Published Oct 7, 2025 Confidentiality and non-disclosure agreements are reviewed periodically to ensure alignment with legal and business requirements. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Background checks in place Human resources security Human resources policies include constituent background screening criteria. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Background checks are performed pre-employment, and periodically as required by industry-specific standards or regulations. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Personnel security procedures in place Human resources security Human resources security policy includes a disciplinary process for non-compliance. Published Oct 7, 2025 Human resources security policy defines constituent accountability for the use and misuse of their access credentials. Published Oct 7, 2025 Terminated constituents understand their continuing information security responsibilities upon termination or role change. Published Oct 7, 2025 Human resources security policy includes onboarding procedures that communicate information security responsibilities to all personnel including contract personnel. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Human resources security policy includes procedures for terminating contract personnel and ensuring information security responsibilities are upheld. Published Oct 7, 2025 Employment agreements established and implemented Human resources security Constituents are required to sign employment agreements. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Employment agreements define personnel information security responsibilities, including acknowledgment of the Code of Conduct and Acceptable Use Policy. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Employment agreements include acknowledgement of confidentiality/non-disclosure policies. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Security training conducted Human resources security Personnel with dedicated information security responsibilities are required to engage in continuing education programs. Published Oct 7, 2025 All new hires are required to complete information security awareness training during onboarding. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT All personnel, regardless of role, are required to complete general information security awareness training at least annually. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information security responsibilities specific to each role are embedded into onboarding and functional training processes. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information security training effectiveness is periodically evaluated to ensure personnel understand and apply security responsibilities. Published Oct 7, 2025 Asset management Controls Asset management program governance in place Asset management program Asset management program is approved by management and includes assigned ownership and responsibilities for maintaining, reviewing, and managing asset controls. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Asset register is maintained. Published Oct 7, 2025 Acceptable use policy for information and associated assets has been developed, communicated and maintained effectively. Published Oct 7, 2025 Information handling policy or procedure developed, communicated and maintained effectively. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT All asset types are identified and recorded in the asset inventory with assigned owners. Published Oct 7, 2025 All organizational assets are prioritized based on classification, criticality, and mission impact. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Asset lifecycle is managed from acquisition through disposal, including reassignment, decommissioning, and return of assets. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Processes ensure the return of all organizational assets upon termination or internal role change, including devices, credentials, and documentation, with responsibilities defined in policy. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Topic-specific policies for information classification, labelling, and transfer are documented, communicated, and maintained. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information classification and data handling policies established Asset management program Information is classified according to legal or regulatory requirements, business value, and sensitivity to unauthorized disclosure or modification. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information handling policy includes storage requirements. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information handling policy defines security requirements for electronic transmission of data, including the use of secure protocols and approved file transfer services. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information handling policy ensures the information's classification is properly labeled in its physical and electronic formats. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Records retention policy and retention schedule cover paper and electronic records. Published Oct 7, 2025 A data retention and destruction policy is implemented that defines storage duration and business/legal requirements for records. Published Oct 7, 2025 Data flows for sensitive information are documented, maintained, and reviewed at least annually. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Authorized internal and external network communication paths and data flows are documented, maintained, and reviewed annually. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Secure data-destruction procedures ensure information and media are irretrievably deleted when no longer required for business, legal, or regulatory purposes. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Data loss prevention (DLP) solution in place Asset management program A data loss prevention (DLP) solution is implemented. Published Oct 7, 2025 Data loss prevention (DLP) security solution includes a handling process if data loss is suspected or occurs. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Measures prevent sensitive, unauthorized, or malicious data from entering AI datasets. Published Oct 7, 2025 Data loss prevention (DLP) security solution covers all relevant data channels, including email, endpoints, cloud storage, and file transfers. Published Oct 7, 2025 Data loss prevention (DLP) solution generates alerts and logs for policy violations, with reporting to responsible teams. Published Oct 7, 2025 Data loss prevention (DLP) policies and rules are reviewed periodically and updated based on evolving threats or compliance requirements. Published Oct 7, 2025 Security tool coverage and effectiveness are monitored via defined metrics. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Encryption and key management procedures established and implemented Asset management program Encryption keys are managed and maintained for scoped data. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Encryption keys are generated in a manner consistent with key management industry standards. Published Oct 7, 2025 Encryption is applied to scoped data at rest, based on data classification and risk. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Encryption is applied to scoped data in transit, based on data classification and risk. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Encryption and key management practices are defined in a documented policy aligned with industry standards. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Only approved cryptographic algorithms and trusted libraries are permitted for encryption and key management. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Security tooling, automation, and integration program established Asset management program Security-specific tools are implemented to support key information security functions. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Security tools supporting key controls are inventoried, with defined owners and documented purpose. Published Oct 7, 2025 Security tooling integrates with operational platforms to support automated or auditable workflows. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Asset management policy enforced Asset management program Procedures and controls for transferring information are defined and enforced. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Scoped data is not sent or received via physical media. Published Oct 7, 2025 Media containing scoped data is securely wiped or destroyed upon disposal, with disposal actions logged and approved. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Chain-of-custody is maintained when transporting data. Published Oct 7, 2025 Supplier-provided services, including systems storing or processing organizational data, are inventoried and reviewed for security compliance. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Mobile device management program in place Endpoint security User endpoint device management program developed and communicated effectively. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Endpoint security configuration standards are implemented, maintained, and apply to all user devices. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Policies and procedures define protection requirements for off-premises use of organizational assets. Published Oct 7, 2025 Endpoint-device configurations are centrally enforced and continuously monitored through secure configuration-management processes. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Enterprise-issued user endpoint devices are registered and configured according to organizational security policies prior to accessing corporate resources. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Enterprise-issued mobile devices are issued to authorized personnel only. Published Oct 7, 2025 Remote wipe or data loss protection is enabled for all user endpoint devices. Published Oct 7, 2025 Registered endpoint devices are reviewed periodically and unauthorized or unused devices are removed. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Personal devices accessing organizational data are subject to mobile application management (MAM) or containerization controls, or are explicitly disallowed. Published Oct 7, 2025 Installation of unapproved or high-risk applications on endpoint devices is restricted based on device type and risk level. Published Oct 7, 2025 Endpoints protected from malicious content Endpoint security Web filter in place to block access to websites containing malicious, illegal, or inappropriate content. Published Oct 7, 2025 Endpoint-protection mechanisms use threat intelligence to block access to known-malicious domains, websites, and IP addresses, and to prevent download or execution of malicious file types. Published Oct 7, 2025 Security event logs are reviewed regularly. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Robust physical security controls implemented Physical security Physical access to secure areas is managed, controlled, and monitored through access mechanisms. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Physical security perimeters use barriers and secured access points. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Physical access control credentials are updated or revoked promptly upon personnel role changes or termination. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Only authorized personnel are granted physical access to secure areas, based on role and business need. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Visitors to secure areas are logged, issued temporary credentials if needed, and escorted at all times. Published Oct 7, 2025 Perimeter controls are reviewed periodically to ensure they remain effective and appropriate to the risk environment. Published Oct 7, 2025 Secure areas are continuously monitored for unauthorized access. Published Oct 7, 2025 Personnel are required to follow documented procedures when working in secure areas, including restrictions on unauthorized devices and activities. Published Oct 7, 2025 Physical protections such as reinforced doors, surveillance systems, and intrusion detection are implemented. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Clear desk and clear screen policies are defined and enforced. Published Oct 7, 2025 Storage media containing sensitive information is protected from unauthorized access, copying, or removal. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Storage media is securely wiped before reassignment or reuse. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Cables carrying data or supporting information services are protected against unauthorized access, interference, or damage. Published Oct 7, 2025 Physical security policy established Physical security A physical security program is established and communicated, with a defined owner. Published Oct 7, 2025 Security perimeters are formally defined and implemented based on risk and business requirements to protect areas containing sensitive information and critical assets. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Physical security program is reviewed at least annually and following significant changes. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Physical security procedures for visitors enforced Physical security Visitors are required to sign in and out and provide valid ID. Published Oct 7, 2025 Visitors required to wear a badge distinguishing them from employees. Published Oct 7, 2025 Visitor logs are maintained for at least 90 days. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Access rights and visitor activity are managed and logged. Published Oct 7, 2025 Activities of visitors and third-party personnel are monitored for potential security incidents. Published Oct 7, 2025 Robust environmental protection controls established Physical security Procedures to address physical and environmental threats have been identified and implemented. Published Oct 7, 2025 Environmental controls include water damage protection measures. Published Oct 7, 2025 Environmental controls include HVAC and humidity controls. Published Oct 7, 2025 Environmental controls include heat and smoke detectors and fire suppression. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Equipment is located in areas protected against fire, flooding, dust, and vibration. Published Oct 7, 2025 Backup and maintenance of critical equipment and systems in place Physical security Critical supporting utilities are designed and implemented. Published Oct 7, 2025 Generator or generator area in offices and facilities. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Maintenance support contracts in place for critical infrastructure and equipment. Published Oct 7, 2025 Infrastructure management Controls Domain ownership protections in place DNS security Domain does not expire soon. Published Oct 7, 2025 Domain has not expired. Published Oct 7, 2025 Domain registrar or registry transfer protection enabled. Published Oct 7, 2025 Domain not flagged as inactive. Published Oct 7, 2025 Domain not pending deletion. Published Oct 7, 2025 Domain not pending restoration. Published Oct 7, 2025 Domain free of registry DNS resolution hold. Published Oct 7, 2025 Domain free of registrar DNS resolution hold. Published Oct 7, 2025 Domain renewal not prohibited by registry. Published Oct 7, 2025 Domain renewal not prohibited by registrar. Published Oct 7, 2025 DNS responses are authenticated DNS security No subdomain takeover vulnerability detected. Published Oct 7, 2025 Proactive measures to reduce unauthorized mailbox access DNS security No unregistered MX records detected. Published Oct 7, 2025 Maintains minimal Wordpress attack surface Internet-facing services (IFS) WordPress XML-RPC API disabled. Published Oct 7, 2025 WordPress version not exposed. Published Oct 7, 2025 Insecure WordPress installation not detected. Published Oct 7, 2025 Outdated WordPress installation not detected. Published Oct 7, 2025 Limits access to frequently exploited products Internet-facing services (IFS) MOVEit Transfer with HTTP and HTTPS port open not detected. Published Oct 7, 2025 MOVEit Transfer with HTTP not available not detected. Published Oct 7, 2025 FortiOS SSL VPN interface not detected. Published Oct 7, 2025 Citrix Gateway not detected. Published Oct 7, 2025 Citrix ADC not detected. Published Oct 7, 2025 Outdated Citrix Gateway version not detected. Published Oct 7, 2025 Outdated Citrix ADC version not detected. Published Oct 7, 2025 Citrix ShareFile not detected. Published Oct 7, 2025 Cisco IOS XE Web UI not detected. Published Oct 7, 2025 Ivanti Connect Secure VPN not detected. Published Oct 7, 2025 GitLab not detected. Published Oct 7, 2025 Removes access to networked management interfaces Internet-facing services (IFS) Veeam Backup software not detected. Published Oct 7, 2025 Prevents compromise of internet-facing systems Internet-facing services (IFS) No indicator of system compromise in Cisco IOS XE Web UI. Published Oct 7, 2025 Potentially malicious Polyfill sources not discovered. Published Oct 7, 2025 Website configurations expose minimal information Website security X-Powered-By header not exposed. Published Oct 7, 2025 Referrer policy is not unsafe-url. Published Oct 7, 2025 ASP.NET version header not exposed. Published Oct 7, 2025 ASP.NET version header not exposing specific ASP.net version. Published Oct 7, 2025 Website configurations prevent clickjacking and cross-site scripting Website security CSP implemented without insecure active sources. Published Oct 7, 2025 CSP implemented without insecure passive sources. Published Oct 7, 2025 Data in transit is encrypted Encryption SSL expiration period shorter than 398 days. Published Oct 7, 2025 SSL chain certificates do not expire within 20 days. Published Oct 7, 2025 Strong encryption used for data in transit Encryption Strong SSL algorithm. Published Oct 7, 2025 Strong public certificate key length. Published Oct 7, 2025 Strong Diffie-Hellman prime used in key exchange. Published Oct 7, 2025 Strong or non-common Diffie-Hellman prime used in key exchange. Published Oct 7, 2025 No insecure cipher suites supported. Published Oct 7, 2025 No weak cipher suites supported in TLS 1.2. Published Oct 7, 2025 Data encrypted with trusted certificate Encryption Certificate not found on our revoked certificate list. Published Oct 7, 2025 Trusted SSL certificate. Published Oct 7, 2025 Proactive measures to reduce unnecessary Wordpress data disclosure Data leakage WordPress user list not exposed. Published Oct 7, 2025 No leaked data detected. Published Oct 7, 2025 Listing of file storage directories is disabled Data leakage No listable directories found. Published Oct 7, 2025 Domain index is not a listable directory. Published Oct 7, 2025 No open cloud storage service detected. Published Oct 7, 2025 Proactive measures to reduce data disclosure to third parties Data leakage Meta/Facebook Pixel not detected. Published Oct 7, 2025 TikTok Pixel not detected. Published Oct 7, 2025 Networks are segregated Network security Networks are segmented into domains with clearly defined perimeters on separate networks, based on a thorough evaluation of each domain’s security requirements. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Networks segmented into domains based on an evaluation of the security requirements for each domain. Published Oct 7, 2025 Client data is logically or physically segregated and isolated from other clients’ data across networks, storage, applications, and backups. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT The rationale for network segmentation decisions is documented and reviewed periodically. Published Oct 7, 2025 Network security policies and procedures in place Network security Management approved policy for remote access to scoped systems and data. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Wireless policy or program has assigned owner and has been approved by management. Published Oct 7, 2025 Security and hardening standards for network devices are defined and enforced. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Safeguards are implemented to detect and block abusive traffic to AI models. Published Oct 7, 2025 Formally defined network security policy is implemented and maintained. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Network architecture incorporates Zero Trust principles such as least privilege access, segmentation, and continuous verification where applicable. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Remote access requires strong authentication (e.g., MFA, VPN with least privilege). Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Remote work requires the use of organization-managed or approved devices with secure configurations. Published Oct 7, 2025 Information accessed, processed, or stored remotely must be protected through secure storage, screen locking, and physical safeguards. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Network traffic and services are continuously monitored to detect anomalies, suspicious activity, and potential indicators of compromise. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Only approved services running Network security No unauthorized open service ports detected. Published Oct 7, 2025 No malicious activity detected IP reputation Not a suspected phishing page. Published Oct 7, 2025 Not a suspected malware provider. Published Oct 7, 2025 Not suspected of unwanted software. Published Oct 7, 2025 No reports of unsolicited scanning in the last 30 days. Published Oct 7, 2025 No reports of unsolicited scanning in the last 90 days. Published Oct 7, 2025 No reports of brute force login attempts in the last 30 days. Published Oct 7, 2025 No reports of brute force login attempts in the last 90 days. Published Oct 7, 2025 No reports of botnet activity in the last 30 days. Published Oct 7, 2025 No reports of botnet activity in the last 90 days. Published Oct 7, 2025 No reports of spam activity in the last 30 days. Published Oct 7, 2025 No reports of spam activity in the last 90 days. Published Oct 7, 2025 No reports of malware distribution in the last 30 days. Published Oct 7, 2025 No reports of malware distribution in the last 90 days. Published Oct 7, 2025 No reports of phishing activity in the last 30 days. Published Oct 7, 2025 No reports of phishing activity in the last 90 days. Published Oct 7, 2025 Email sender authenticated Email security SPF syntax correct. Published Oct 7, 2025 Strict SPF filtering - not using +all. Published Oct 7, 2025 Strict SPF filtering - not using ?all. Published Oct 7, 2025 Strict SPF filtering - not using ~all. Published Oct 7, 2025 SPF ptr mechanism not used. Published Oct 7, 2025 DMARC policy is not p=none. Published Oct 7, 2025 DMARC policy is not p=quarantine. Published Oct 7, 2025 DMARC policy percentage is default. Published Oct 7, 2025 Data protection Controls Access control processes established and implemented Access management Periodic user access reviews are conducted. Published Oct 16, 2025 Unique IDs are required for authentication across systems and devices. Published Oct 16, 2025 SOC 2 TYPE 2 REPORT User access rights are granted on a least-privilege basis, aligned with each role’s business needs. Published Oct 16, 2025 Process in place to modify access rights of users who have changed roles. Published Oct 16, 2025 Inactive user IDs disabled or deleted after defined periods of inactivity. Published Oct 16, 2025 Process that allows authenticators to be revoked when necessary. Published Oct 16, 2025 Use of privileged accounts is logged and monitored to detect misuse or unauthorized activity. Published Oct 16, 2025 Access exceptions and temporary access are documented, time-bound, and approved through a formal process. Published Oct 16, 2025 Use of privileged utility programs is restricted, approved, and monitored. Published Oct 16, 2025 Access to information and other associated assets is restricted through technical and procedural controls. Published Oct 16, 2025 Privileged access rights are reviewed at least quarterly. Published Oct 16, 2025 Policies include prompt removal of physical and logical access rights upon termination or change of employment. Published Oct 16, 2025 Identities are verified prior to provisioning access to systems and services. Published Oct 16, 2025 Identity lifecycle processes are implemented to provision, update, and revoke access for all user and system identities. Published Oct 16, 2025 Users are informed of their responsibilities for protecting access credentials and securely accessing information and systems. Published Oct 16, 2025 Access provisioning and deprovisioning are automated and integrated with HR or identity lifecycle processes. Published Oct 16, 2025 Identity assertions are cryptographically protected, securely transmitted, and verified prior to granting access. Published Oct 16, 2025 Documented access control policy in place Access management Access control policy approved by senior management, maintained and communicated effectively. Published Oct 16, 2025 Segregation of duties in place for granting and approving access to scoped systems and data. Published Oct 16, 2025 SOC 2 TYPE 2 REPORT Privileged accounts are kept distinct from standard accounts, and their use is documented and restricted to only those key roles that require them. Published Oct 16, 2025 Authentication mechanisms are securely implemented and enforced Access management Processes in place to protect passwords and PIN numbers. Published Oct 16, 2025 Authentication policy is documented, approved, and enforced across all authentication mechanisms and systems. Published Oct 16, 2025 Authentication credentials are securely distributed to users following identity verification. Published Oct 16, 2025 SOC 2 TYPE 2 REPORT Processes are in place to securely reset or recover authentication credentials when required. Published Oct 16, 2025 Phishing-resistant authentication methods are adopted where feasible based on risk. Published Oct 16, 2025 Authentication mechanisms protect against brute-force attacks. Published Oct 16, 2025 Multi-factor authentication is enforced for user access to non-public organizational systems and applications. Published Oct 16, 2025 Multi-factor authentication required for privileged system access. Published Oct 16, 2025 Multi-factor authentication enforced for all endpoint access. Published Oct 16, 2025 Compliance with MFA requirements is monitored and reviewed regularly to ensure enforcement across all applicable systems. Published Oct 16, 2025 SSO is enforced across all organizational systems and applications, including both internal and third-party applications. Published Oct 16, 2025 All SSO logins require multi-factor authentication (MFA). Published Oct 16, 2025 SSO authentication events and anomalies (e.g., failed logins, location mismatches) are monitored and integrated with security alerting. Published Oct 16, 2025 SOC 2 TYPE 2 REPORT Administrative access to the SSO platform requires just-in-time elevation or additional verification. Published Oct 16, 2025 Access management audit trail Access management User access records are retained for at least 12 months. Published Oct 7, 2025 Session timeouts and reauthentication requirements are enforced based on risk level and inactivity thresholds. Published Oct 7, 2025 Data privacy and protection policy in place Privacy management Data privacy and protection policy has been implemented. Published Oct 16, 2025 Formal privacy program covers for the protection of personal information handled on behalf of the client. Published Oct 16, 2025 Data subjects can request removal of their personal data from AI systems where feasible. Published Oct 16, 2025 A privacy impact assessment (PIA) process is established and integrated into new system, service, or vendor onboarding. Published Oct 16, 2025 The privacy policy explicitly aligns with applicable national and international privacy regulations. Published Oct 16, 2025 The privacy policy is reviewed and re-approved at least annually or upon material change. Published Oct 16, 2025 Safe handling of Personally Identifiable Information (PII) Privacy management PII is classified and labeled according to sensitivity, with corresponding handling requirements. Published Oct 16, 2025 Documented policies and procedures to address cross-border and international data flows. Published Oct 16, 2025 PII disposal is logged and verified to prevent unauthorized retention. Published Oct 16, 2025 Clear accountability for privacy obligations Privacy management A qualified and accountable owner is designated to oversee the privacy programme and ensure compliance with all privacy requirements, including contractual client-data obligations. Published Oct 16, 2025 Publicly facing communication channels in place to enable submission and response to privacy inquiries, complaints, and disputes. Published Oct 16, 2025 SOC 2 TYPE 2 REPORT Roles and responsibilities for privacy risk management are documented, including escalation paths. Published Oct 16, 2025 Privacy management encompasses third and fourth parties Privacy management Contracts and agreements with third parties include appropriate data protection safeguards. Published Oct 16, 2025 Third-party risk management program covers security of client scoped data. Published Oct 16, 2025 Cybersecurity responsibilities for third parties and customers are documented, communicated, and coordinated across internal stakeholders and external entities. Published Oct 16, 2025 SOC 2 TYPE 2 REPORT Third-party due diligence includes evaluation of data protection and privacy policies, practices, and technical controls. Published Oct 16, 2025 SOC 2 TYPE 2 REPORT Third-party data access and transmission are explicitly disclosed and approved. Published Oct 16, 2025 Application security Controls Secure software development practices Software development A secure development life cycle process is defined, implemented, and integrated into all development projects. Published Oct 16, 2025 Software development, testing, and staging environments are kept separate from the production environment. Published Oct 16, 2025 Security experts are engaged for development on all applications. Published Oct 16, 2025 Third-party or outsourced development is governed by security requirements, auditability, and contract clauses. Published Oct 16, 2025 Secure code reviews include analysis of vulnerability to recent attacks. Published Oct 16, 2025 Web server patches, service packs, and hot fixes are tested, documented, and approved prior to deployment. Published Oct 16, 2025 SOC 2 TYPE 2 REPORT Access to development, test, and production environments is role-based and uses separate credentials. Published Oct 16, 2025 Outsourced development is actively supervised and monitored. Published Oct 16, 2025 Security testing processes are formally defined and implemented during development and acceptance stages. Published Oct 16, 2025 Secure coding standards are defined and applied throughout the development process. Published Oct 16, 2025 Security fixes and patches are rolled out according to defined severity-based timelines. Published Oct 16, 2025 AI systems are assessed for known risks using established adversarial threat models. Published Oct 16, 2025 Static and dynamic application security testing (SAST/DAST) is integrated into continuous integration/continuous deployment pipelines. Published Oct 16, 2025 Audit activities involving operational systems are planned in advance and approved by relevant management. Published Oct 16, 2025 Access granted for audit or assurance testing is limited to the minimum level required, authorized prior to use, and logged. Published Oct 16, 2025 Security testing tools and auditor devices are verified to meet organizational security requirements before accessing operational systems. Published Oct 16, 2025 Secure architecture design standards established Software development Management approved IT architectural plan. Published Oct 7, 2025 Secure design principles are documented and consistently applied across system architecture and engineering processes. Published Oct 7, 2025 Architecture reviews are conducted to validate that secure design principles are applied consistently. Published Oct 7, 2025 Baseline secure configurations are defined and regularly reviewed for all hardware, software, services, and networking assets. Published Oct 7, 2025 Configuration changes are logged and monitored for unauthorized modifications. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Developer security training implemented Software development Developers receive formal, role-specific training on secure coding, threat modeling, and privacy engineering as part of onboarding and annual refreshers. Published Oct 7, 2025 Test data procedures implemented Software development Sensitive information is not used in the test, development, or QA environments. Published Oct 7, 2025 Authorization is required if production data is copied to the test environment. Published Oct 7, 2025 Test data securely is destroyed following testing. Published Oct 7, 2025 Where production data is used for testing, it is masked, anonymized, or tokenized. Published Oct 7, 2025 All test data is subject to the same classification and destruction policy as production data. Published Oct 7, 2025 Developer access management Software development Policy and procedures in place to control access to source code and development tools. Published Oct 7, 2025 Developer access to production environments is controlled. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Developer access to production environments uses just-in-time elevation or temporary tokens. Published Oct 7, 2025 Access to source code is version-controlled and monitored for unauthorized changes. Published Oct 7, 2025 Security analysis tools are used to detect defects in source code prior to production deployment. Published Oct 7, 2025 Vulnerability management program established Vulnerability management Vulnerability management program and policy has been effectively developed and maintained. Published Oct 7, 2025 Vulnerability scans are performed on a defined cadence, covering all internet-exposed and internal assets. Published Oct 7, 2025 Risk-based prioritization is applied using CVSS and/or exploitability data. Published Oct 7, 2025 Time-to-remediate targets are defined and tracked for high, medium, and low vulnerabilities. Published Oct 7, 2025 Supported software versions are maintained Vulnerability management No products with an upcoming end of life detected. Published Oct 7, 2025 No products with discretionary support detected. Published Oct 7, 2025 Known vulnerabilities remediated Vulnerability management No known vulnerabilities detected. Published Oct 7, 2025 Penetration testing program in place Vulnerability management Third-party web application penetration tests are conducted. Published Oct 7, 2025 Penetration testing has a defined scope including web applications, internal infrastructure, and APIs where applicable. Published Oct 7, 2025 Penetration test findings are tracked and remediated through a formal process. Published Oct 7, 2025 Special interest group membership Vulnerability management Documented evidence of membership to forums relating to information security (such as ISC2, ISACA, OWASP), with an assigned role to monitor and feed insights back into the security program. Published Oct 7, 2025 Risk management Controls Formalized risk assessment process Enterprise risk management Formal risk assessment process is defined and implemented. Published Oct 7, 2025 Cybersecurity risk appetite and risk tolerance statements are formally documented, communicated to relevant stakeholders, and reviewed on a defined schedule. Published Oct 7, 2025 Information assets and business processes are inventoried and evaluated for risk exposure as part of the risk assessment process. Published Oct 7, 2025 Risk assessments are reviewed at planned intervals and upon major changes to the business environment or threat landscape. Published Oct 7, 2025 Risk status and treatment outcomes are regularly communicated to enterprise risk stakeholders and incorporated into enterprise risk management (ERM) decision-making processes. Published Oct 7, 2025 3rd-Nth party risk management program enforced Third-Nth party management A third-party risk management (TPRM) program is established and implemented. Published Oct 7, 2025 All suppliers are identified and prioritized based on the criticality of their products or services to operations and cybersecurity posture. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Third-party risk management program policies, standards, and procedures are reviewed and approved by senior management. Published Oct 7, 2025 Third-party risk management process includes onboarding and offboarding procedures for vendors. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Critical suppliers are identified and assessed for cybersecurity risks prior to acquisition or onboarding. Published Oct 7, 2025 Third-party risk management program includes a definition of contract development, adherence and management policies and processes. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Third parties are continuously monitored for security risk, compliance, and performance throughout the lifecycle of their products and services. Published Oct 7, 2025 Third-parties or service providers are evaluated for reassessment when there are material changes to risk posture, service offerings or contracts. Published Oct 7, 2025 Cybersecurity risks from suppliers and third parties are included in risk communication across relevant business units and leadership. Published Oct 7, 2025 Third-party risk management program requires third parties to disclose and provide visibility into their 3rd/Nth party dependencies. Published Oct 7, 2025 Third-party risk management program includes requirements for traceability of subcontracted services or software components. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Third-party risk management program includes consideration of 4th and Nth parties in the ICT supply chain. Published Oct 7, 2025 Third-party risk program defines periodic and event-based reassessment criteria. Published Oct 7, 2025 Cloud services are evaluated for security risks and compliance prior to acquisition or use. Published Oct 7, 2025 Cloud services are configured and monitored in accordance with defined security policies and contractual requirements. Published Oct 7, 2025 Exit strategies and processes are documented for cloud services. Published Oct 7, 2025 Hardware and software are verified for authenticity and integrity prior to acquisition or use, using trusted sources and validation mechanisms. Published Oct 7, 2025 Supply chain risk considerations are integrated into enterprise risk management activities, including risk registers, strategy reviews, and prioritization processes. Published Oct 7, 2025 Supply chain security practices are integrated into the organization's cybersecurity and enterprise risk management programs. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Contractual obligations cover Nth parties Third-Nth party management Third-party contracts obligate sub-suppliers (4th/Nth parties) to implement privacy and information-security controls equivalent to those required of the primary supplier. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT All third-party and outsourced service provider relationships require confidentiality and/or non-disclosure agreements. Published Oct 7, 2025 Third-party contracts include fourth/Nth party privacy and security control requirements where applicable. Published Oct 7, 2025 Third-party contracts require notification within a defined timeframe upon breach or significant incident. Published Oct 7, 2025 Contracts include the right to audit or request evidence of compliance from subcontractors and 4th parties. Published Oct 7, 2025 Data processing agreements and security/privacy clauses are mandated in all third-party contracts involving personal or sensitive data. Published Oct 7, 2025 Operational resilience Controls Backup processes implemented Business continuity Scoped data backed up and stored offsite. Published Oct 16, 2025 Backup and related restoration procedures tested at least annually. Published Oct 16, 2025 Backup procedure in place for all information, software, and systems. Published Oct 16, 2025 Backup data is encrypted in transit. Published Oct 16, 2025 Backup data is encrypted at rest. Published Oct 16, 2025 Backup data is protected from unauthorized access. Published Oct 16, 2025 Backup procedures clearly define recovery point objectives (RPO) and recovery time objectives (RTO), which are reviewed and updated based on risk and business impact. Published Oct 16, 2025 SOC 2 TYPE 2 REPORT Immutable or isolated backup copies are maintained, preventing modification or deletion for a defined retention period. Published Oct 16, 2025 SOC 2 TYPE 2 REPORT Business continuity plans in place Business continuity Formal procedures for business continuity have been developed and documented. Published Oct 7, 2025 Procedures are in place to ensure ICT continuity plans are regularly tested, evaluated for effectiveness, and approved by management. Published Oct 7, 2025 Business continuity procedures include the continuity of information security activities and processes including intrusion detection, vulnerability management and log collection. Published Oct 7, 2025 Business continuity plans include specific provisions for cloud-hosted services, including roles and responsibilities shared with cloud providers. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information security requirements (confidentiality, integrity, and availability) are maintained during disruptions. Published Oct 7, 2025 Redundancy mechanisms for critical systems are tested regularly. Published Oct 7, 2025 Technical redundancy mechanisms are implemented to prevent downtime and ensure continuous system operation during outages. Published Oct 7, 2025 System and infrastructure resource usage is monitored and adjusted to meet current and forecasted capacity needs, including stress testing of critical systems. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Integrity of restored systems and data is verified after an incident, and restoration is confirmed complete only after systems return to normal operating status. Published Oct 7, 2025 Contingency measures are implemented to ensure business continuity during critical AI system disruptions. Published Oct 7, 2025 Disaster recovery procedures established Business continuity Disaster recovery procedure in place to restore the security of information for critical business processes in the event of an interruption or failure. Published Oct 7, 2025 Disaster recovery procedure in place to ensure that there are appropriate personnel ready to deal with any disruptions. Published Oct 7, 2025 Formal disaster recovery procedures include specific actions to be taken in response to a disruptive event for each affected area. Published Oct 7, 2025 Proactive detection of potential incidents Cybersecurity incident management Regular reviews of events are conducted to detect suspicious activity or potential incidents affecting systems with scoped data. Published Oct 7, 2025 Regular security monitoring includes alerts for malware infections and suspicious activity. Published Oct 7, 2025 A proactive detection capability is established and maintained . Published Oct 7, 2025 Detection processes include automated correlation of logs, threat intelligence, and anomaly detection across endpoints, network, and cloud. Published Oct 7, 2025 Threat intelligence from internal and external sources is collected and analysed to identify adversary tactics, techniques, and procedures (TTPs). Published Oct 7, 2025 A documented process is in place to receive, analyze, and respond to vulnerability disclosures from internal and external sources, including coordinated disclosure from researchers or third parties. Published Oct 7, 2025 Security alerts are tuned for false positives, prioritized based on asset criticality, and reviewed regularly. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Incident Management_V1.2_240430 Detection and response capabilities are thoroughly tested, and improvements from these exercises are identified and implemented. Published Oct 7, 2025 Adversarial threat detection techniques and remediation steps address data poisoning or evasion attacks against AI models. Published Oct 7, 2025 Incident response plan in place Cybersecurity incident management Cybersecurity Incident Management Program is approved and has a designated owner. Published Oct 7, 2025 Incident-management programme has a clearly defined scope that includes all systems, networks, applications, endpoints, cloud environments, third-party services, and AI-driven systems where applicable. Published Oct 7, 2025 Incident response plan includes a detailed action plan in the event of a security breach. Published Oct 7, 2025 Incident response plan includes an escalation process with defined escalation paths and internal communication protocols. Published Oct 7, 2025 Incident response plan includes notifying authorities and customers of serious data breaches. Published Oct 7, 2025 Clocks are synchronized to enable correlation and analysis of security-related events and other recorded logging data. Published Oct 7, 2025 Incident response plan recovery phase is executed following containment and eradication and requires remediation of any affected systems discovered after incident closure. Published Oct 7, 2025 Lessons learned from information security incidents are documented and used to improve detection capabilities, response procedures, and preventive controls. Published Oct 7, 2025 Procedures ensure prompt response and communication of operational impacts from degraded AI performance or biased outputs. Published Oct 7, 2025 Incident response roles and responsibilities are assigned and communicated to relevant personnel, and reviewed regularly. Published Oct 7, 2025 Confirmed security incidents are promptly contained through defined procedures. Published Oct 7, 2025 Confirmed incidents are eradicated through defined procedures. Published Oct 7, 2025 Incident response plans cover all potential incident types. Published Oct 7, 2025 All incident reports are triaged and validated through a defined process before escalation or response activities are initiated. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Information security events are assessed using a defined process to determine whether they should be classified as incidents. Published Oct 7, 2025 Incident classification criteria include data classification, impact to operations, regulatory exposure, and system criticality. Published Oct 7, 2025 Incident details are shared with designated internal and external stakeholders during response activities. Published Oct 7, 2025 Incident response and recovery plans include participation of relevant third parties and suppliers, with defined roles, communication procedures, and testing. Published Oct 7, 2025 SOC 2 TYPE 2 REPORT Criteria for initiating the recovery phase are defined, documented, and applied during incident response. Published Oct 7, 2025 Incident response recovery actions are selected, scoped, and prioritized based on system criticality and business impact. Published Oct 7, 2025 Recovery progress is communicated to designated internal and external stakeholders. Published Oct 7, 2025 Public updates on recovery progress are shared through approved channels using defined messaging. Published Oct 7, 2025 Incident recovery is formally closed based on defined criteria, with all incident documentation completed. Published Oct 7, 2025 Root cause analysis is performed for all significant information security incidents. Published Oct 7, 2025 Relevant authorities are identified and appropriate organizational contacts are established and maintained. Published Oct 7, 2025 Security events are analyzed in real time or near real time to assess their scope, potential business impact, and criticality. Published Oct 7, 2025 Information security incidents are recorded, tracked through resolution, and retained to support incident response improvement and reporting. Published Oct 7, 2025 Procedures are in place to identify, collect, and preserve information relevant to security events and incidents for use as evidence. Published Oct 7, 2025