Snapshot 41552
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Monitored and Powered by Trust Center koalendar.com [email protected] Compliance overview Current compliance status across frameworks SOC 2 Type 2 Compliant Featured documents Key security and compliance documentation Koalender Final Report Request access Q1 2026 Koalendar Pentest Request access View all documents Compliance Program An overview of security controls in place Access Control and Authorization Access granting process used Access management policy established Account inventory maintained Dormant accounts disabled Employee access regularly reviewed MFA required for administrative access MFA required for applications MFA required for critical services MFA required for infrastructure access Password management policy enforced Password management policy established Data Management and Protection Data encrypted at rest Data encrypted in-transit Data inventory maintained Data management and retention policy established Data masking procedures used Privacy policy created and maintained Disaster Recovery Automated backups enabled Business continuity and disaster recovery policy established Data backup and recovery policy established Data recovery process established Disaster recovery plans tested Recovery data isolated Email Security DMARC policy and verification used Email account access restricted Email settings block malicious content Endpoint Security Anti-malware deployed on end-user devices Automatic session locking enforced Data encrypted on end-user devices Firewall maintained on end-user devices Mobile device management (MDM) used Infrastructure Security Active discovery tools used Administrator access restricted Automated security scanning performed on infrastructure Buckets not exposed publicly Configuration management system established Firewall restricts public access to infrastructure Infrastructure changes logged Infrastructure changes require review Infrastructure deployed using an infrastructure-as-code tool Key management policy established Production deployment access restricted Unauthorized assets addressed and removed Unique production database authentication enforced Web Application Firewall (WAF) used Monitoring and Incident Response Adequate audit log storage maintained Audit log management process maintained Audit logs collected Breach notification process established Incident response exercises performed Incident response policy established Incident review process implemented Infrastructure performance monitored Log management used Network infrastructure monitored Organizational Security Acceptable use policy established Asset inventory maintained Asset management policy established Change management policy established Changelog established and maintained Code of conduct established Company security commitments externally communicated Confidentiality Agreement acknowledged by contractors Confidentiality Agreement acknowledged by employees Data-flow diagrams maintained External support resources available (i.e., documentation) HIPAA training conducted Information security program established Offboarding process established Onboarding process established Operational procedures maintained Performance evaluations conducted Physical access restricted Physical security policy established Policies signed by relevant personnel Reference checks performed for employees Roles and responsibilities specified Security awareness training conducted Service description communicated Software development lifecycle established System changes externally communicated System changes internally communicated Third-party security oversight conducted Risk Management Risk assessments performed Risk management policy established Software supply chain risks monitored Vendor inventory maintained Vendor management policy established Vendor management program established Vulnerability Management Automated software patch management performed Penetration testing findings remediated Penetration testing performed within the last 12 months Vulnerabilities scanned Vulnerability management policy established