Snapshot 58622
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Monitored and Powered by Trust Center Everything you need for security and compliance commonpaper.com status.commonpaper.com security@commonpaper.com Compliance overview Current compliance status across frameworks SOC 2 Type 2 In progress Featured documents Key security and compliance documentation Q4 2024 Common Paper Pentest Request access Q1 2026 Common Paper Pentest Request access Common Paper SOC 2 Type 2 Report Request access View all documents Compliance Program An overview of security controls in place Access Control and Authorization Access management policy established Account inventory maintained Dormant accounts disabled Employee access regularly reviewed MFA required for critical services Data Management and Protection Data encrypted at rest Data encrypted in-transit Data management and retention policy established Disaster Recovery Automated backups enabled Business continuity and disaster recovery policy established Disaster recovery plans tested Email Security DMARC policy and verification used Email settings block malicious content Endpoint Security Anti-malware deployed on end-user devices Data encrypted on end-user devices Firewall maintained on end-user devices Mobile device management (MDM) used Infrastructure Security Active discovery tools used Automated security scanning performed on infrastructure Buckets not exposed publicly Cloud infrastructure used Firewall restricts public access to infrastructure Production deployment access restricted Monitoring and Incident Response Incident response policy established Incident review process implemented Infrastructure performance monitored Organizational Security Board charter documented Board oversight briefings conducted Changelog established and maintained Code of conduct established Company security commitments externally communicated Data-flow diagrams maintained Employee background checks performed External support resources available (i.e., documentation) Internal security audit performed Offboarding process established Onboarding process established Password manager used Performance evaluations conducted Physical access restricted Policies signed by relevant personnel Roles and responsibilities specified Security awareness training conducted Service description communicated Software development lifecycle established Third-party security oversight conducted Risk Management Risk assessments performed Risk management policy established Software supply chain risks monitored Vendor inventory maintained Vendor management program established Vulnerability Management Automated software patch management performed Penetration testing findings remediated Penetration testing performed within the last 12 months Vulnerabilities scanned Vulnerability management policy established