Snapshot 48586
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Monitored and Powered by Trust Center bigmind.ai bigmind.instatus.com [email protected] Compliance overview Current compliance status across frameworks SOC 2 Type 2 Compliant SOC 2 Type 2 Compliant SOC 2 Type 2 Compliant Featured documents Key security and compliance documentation Bigmind SOC2 Type 2 CPA Report (1) Request access Q3 2025 Bigmind Pentest Request access View all documents Compliance Program An overview of security controls in place Access Control and Authorization Access granting process used Access management policy established Dormant accounts disabled MFA required for critical services Password management policy established Data Management and Protection Data deletion enforced Data encrypted at rest Data encrypted in-transit Data inventory maintained Data labeled according to classification level Data management and retention policy established Disaster Recovery Business continuity and disaster recovery policy established Data recovery process established Data recovery tested Disaster recovery plans tested Email Security DMARC policy and verification used Email account access restricted Email settings block malicious content Endpoint Security Anti-malware deployed on end-user devices Data encrypted on end-user devices Firewall maintained on end-user devices Mobile device management (MDM) used Infrastructure Security Active discovery tools used High availability infrastructure used Infrastructure changes logged Infrastructure changes require review Production deployment access restricted Unauthorized assets addressed and removed Web Application Firewall (WAF) used Monitoring and Incident Response Audit log management process maintained Audit logs collected Incident response policy established Incident review process implemented Organizational Security Acceptable use policy established Asset inventory maintained Asset management policy established Change management policy established Changelog established and maintained Code of conduct established Company security commitments externally communicated Data-flow diagrams maintained External support resources available (i.e., documentation) Offboarding process established Onboarding process established Performance evaluations conducted Physical access restricted Policies signed by relevant personnel Security awareness training conducted Service description communicated Software development lifecycle established System changes externally communicated System changes internally communicated Risk Management Risk management policy established Vendor inventory maintained Vendor management program established Vulnerability Management Automated software patch management performed Penetration testing findings remediated Penetration testing performed within the last 12 months Vulnerability management policy established