Snapshot 49573
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Monitored and Powered by Trust Center www.sero.so hello@sero.so Compliance overview Current compliance status across frameworks GDPR In progress ISO 27001 In progress SOC 2 Type 2 In progress Featured documents Key security and compliance documentation Sero Q4 2023 Pentest Request access View all documents Compliance Program An overview of security controls in place Access Control and Authorization Access granting process used Account inventory maintained Employee access regularly reviewed MFA required for administrative access Password management policy enforced Data Management and Protection Data encrypted at rest Data encrypted in-transit Data inventory maintained Data management and retention policy established Disaster Recovery Automated backups enabled Business continuity and disaster recovery policy established Data recovery process established Disaster recovery plans tested Recovery data isolated Email Security DMARC policy and verification used Email account access restricted Infrastructure Security Active discovery tools used Automated security scanning performed on infrastructure Configuration management system established Infrastructure changes logged Infrastructure changes require review Infrastructure deployed using an infrastructure-as-code tool Unauthorized assets addressed and removed Unique production database authentication enforced VPN used Web Application Firewall (WAF) used Monitoring and Incident Response Audit log management process maintained Audit logs collected Incident response policy established Network infrastructure monitored Organizational Security Acceptable use policy established Asset inventory maintained Asset management policy established Code of conduct acknowledged by employees Code of conduct established Company security commitments externally communicated Confidentiality Agreement acknowledged by employees Data-flow diagrams maintained Performance evaluations conducted Physical access restricted Reference calls performed for employees Roles and responsibilities specified Security awareness training conducted Software development lifecycle established System changes externally communicated System changes internally communicated Risk Management Risk assessments performed Risk management policy established Vendor inventory maintained Vendor management program established Vulnerability Management Automated software patch management performed Penetration testing findings remediated Vulnerabilities remediated Vulnerability management policy acknowledged by employees Vulnerability management policy established