Snapshot 48680
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Monitored and Powered by Trust Center pollen.cx [email protected] Compliance overview Current compliance status across frameworks SOC 2 Type 1 Compliant Featured documents Key security and compliance documentation Engagement Letter - Pollen Request access Incident Response Policy Request access Vendor Management Policy Request access View all documents Compliance Program An overview of security controls in place Access Control and Authorization Access management policy established Account inventory maintained Dormant accounts disabled Employee access regularly reviewed MFA required for applications MFA required for critical services Password management policy established Data Management and Protection Data encrypted in-transit Data inventory maintained Data is encrypted at rest using customer-controlled keys Data management and retention policy established Disaster Recovery Automated backups enabled Business continuity and disaster recovery policy established Disaster recovery plans tested Email Security DMARC policy and verification used Email account access restricted Email settings block malicious content Endpoint Security Anti-malware deployed on end-user devices Automatic session locking enforced Data encrypted on end-user devices Firewall maintained on end-user devices Mobile device management (MDM) used Infrastructure Security Active discovery tools used Automated security scanning performed on infrastructure Buckets not exposed publicly Cloud infrastructure used Firewall restricts public access to infrastructure Pull requests used Unauthorized assets addressed and removed Monitoring and Incident Response Adequate audit log storage maintained Audit logs collected Incident response policy established Infrastructure performance monitored Organizational Security Acceptable use policy established Asset inventory maintained Asset management policy established Change management policy established Code of conduct established Company security commitments externally communicated Data-flow diagrams maintained HIPAA training conducted Offboarding process established Onboarding process established Password manager used Physical access restricted Physical security policy established Policies signed by relevant personnel Reference checks performed for employees Security awareness training conducted Service description communicated Software development lifecycle established Third-party security oversight conducted Whistleblower policy established Risk Management Risk assessments performed Risk management policy established Software supply chain risks monitored Vendor inventory maintained Vendor management program established Vulnerability Management Penetration testing findings remediated Penetration testing performed within the last 12 months Vulnerabilities scanned Vulnerability management policy established