Third Party Index

Snapshot 55449

Document
Trust center
URL
https://trust.sanka.com/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
102440 bytes
SHA-256 (raw)
4be8d3be222146364682a072df6de0fe8685571a8ce2c26c8c1ef4a7da45fd4f
SHA-256 (normalized text)
f50559a21733d0582bb47c42d91fc1c6f63d13d0949b1be2be1dc35f22433768

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Monitored and Powered by
Sanka Trust Center
Security, privacy, compliance, and operational assurance for the Sanka platform.
sanka.com
status.sanka.com
hey@sanka.com
Compliance overview
Current compliance status across frameworks
ISO 27001
In progress
SOC 2 Type 2
In progress
Compliance Program
An overview of security controls in place
Access Control and Authorization
Access granting process used
Access management policy established
Access requests to sensitive data required
Access requests to sensitive infrastructure required
Access revoking process enforced
Dedicated administrator accounts used
Dormant accounts disabled
Employee access regularly reviewed
MFA required for administrative access
MFA required for critical services
MFA required for infrastructure access
Password management policy established
Data Management and Protection
Data deletion enforced
Data encrypted in-transit
Data inventory maintained
Data is encrypted at rest
Data labeled according to classification level
Data management and retention policy established
Data masking procedures used
Key management process implemented
Disaster Recovery
Automated backups enabled
Business continuity and disaster recovery policy established
Business continuity plans documented
Business impact analysis performed
Data backup and recovery policy established
Data recovery process established
Data recovery tested
Disaster recovery plans tested
Recovery data isolated
Email Security
DMARC policy and verification used
Email account access restricted
Email settings block malicious content
Endpoint Security
Anti-malware deployed on end-user devices
Automatic session locking enforced
Data encrypted on end-user devices
Firewall maintained on end-user devices
Software inventory on end-user devices maintained
Infrastructure Security
Active discovery tools used
Administrator access restricted
Anti-malware deployed on infrastructure
Automated security scanning performed on infrastructure
Buckets not exposed publicly
Clock synchronization enforced
Cloud infrastructure used
Configuration management system established
Firewall restricts public access to infrastructure
High availability infrastructure used
Infrastructure changes require review
Infrastructure deployed using an infrastructure-as-code tool
Key management policy established
Network security policy established
Production and test environments separated
Production deployment access restricted
Pull requests used
Unauthorized assets addressed and removed
Unique production database authentication enforced
Monitoring and Incident Response
Audit log management process maintained
Audit logs collected
Compliance monitoring processes defined and implemented
Incident response policy established
Infrastructure performance monitored
Log management used
Logging and monitoring policy established
Network infrastructure monitored
Threat intelligence established
Organizational Security
Acceptable use policy established
Asset inventory maintained
Asset management policy established
Change management policy established
Code of conduct established
Communication procedure established
Company security commitments externally communicated
Data-flow diagrams maintained
Documentation procedure established
Employment contracts used
Human resource security policy established
Information security communities identified
Information security in project management integrated
Information security policy established
Internal security communication maintained
Leadership security commitment established
Management review implemented
Network diagrams maintained
Non-conformance and corrective action procedures established
Offboarding process established
Onboarding process established
Operational procedures maintained
Password manager used
Performance evaluations conducted
Physical access restricted
Physical security policy established
Policies signed by relevant personnel
Reference checks performed for employees
Relevant authorities identified
Remote work policy established
Resources for ISMS available
Roles and responsibilities specified
Scope for compliance framework established
Security awareness training conducted
Security official assigned
Service description communicated
Software development lifecycle established
Statement of applicability completed
System changes externally communicated
System changes internally communicated
Third-party security oversight conducted
Vendor agreements established
Risk Management
Compliance policy established
Internal audit program defined
Outsourced development secured
Risk assessments performed
Risk management policy established
Risk owners identified
Risk treatment plans established
Software supply chain risks monitored
Vendor inventory maintained
Vendor management policy established
Vendor management program established
Vulnerability Management
Penetration testing findings remediated
Penetration testing performed within the last 12 months
Vulnerabilities scanned
Vulnerability management policy established