Third Party Index

Snapshot 56747

Document
Trust center
URL
https://trust.caretta.so/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
78718 bytes
SHA-256 (raw)
af16c29513dcb16c59e6dc97f4f86af84a913ee457c58be32e017c5fcf111e4e
SHA-256 (normalized text)
a4d5bea4fe8ba1408489eabbc8028eec13c2b7758663cb09304cf93819e12537

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Monitored and Powered by
Trust Center
caretta.so
Compliance overview
Current compliance status across frameworks
SOC 2
In progress
GDPR
In progress
Compliance Program
An overview of security controls in place
Access Control and Authorization
Access granting process used
Access management policy established
Account inventory maintained
Automated decision-making and profiling has oversight
Dormant accounts disabled
MFA required for critical services
Password management policy enforced
Password management policy established
Data Management and Protection
Consent for collecting and managing data obtained
Criminal record data processing managed
Data encrypted at rest
Data encrypted in-transit
Data inventory maintained
Data management and retention policy established
Data processing integrity and output validated
Data transfer mechanisms established
External privacy inquiries managed
Privacy disclosure and notification mechanisms established
Privacy policy created and maintained
Disaster Recovery
Automated backups enabled
Business continuity and disaster recovery policy established
Data recovery process established
Disaster recovery plans tested
Email Security
DMARC policy and verification used
Email settings block malicious content
Endpoint Security
Anti-malware deployed on end-user devices
Data encrypted on end-user devices
Firewall maintained on end-user devices
Mobile device management (MDM) used
Infrastructure Security
Active discovery tools used
Automated security scanning performed on infrastructure
Buckets not exposed publicly
Cloud infrastructure used
Firewall restricts public access to infrastructure
Monitoring and Incident Response
Audit log management process maintained
Breach notification process established
Incident response policy established
Organizational Security
Acceptable use policy established
Asset management policy established
Code of conduct established
Company security commitments externally communicated
Information security program established
Internal privacy policies established
Internal security audit performed
Onboarding process established
Operational procedures maintained
Password manager used
Physical access restricted
Policies signed by relevant personnel
Reference checks performed for employees
Relevant authorities identified
Roles and responsibilities specified
Security awareness training conducted
Service description communicated
Software development lifecycle established
Third-party security oversight conducted
Vendor agreements established
Risk Management
Data Protection Impact Assessment (DPIA) completed
Risk assessments performed
Risk management policy established
Software supply chain risks monitored
Vendor management program established
Vulnerability Management
Penetration testing performed within the last 12 months
Vulnerabilities scanned
Vulnerability management policy established