Snapshot 64627
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Puzzel Trust Center Resources See section Resources ISO 27001 Certificate ISO 27701 certificate ISO audit report Cyber Essentials Sub-processors and subcontractors SOC 2 Type II SOC 2 Type II report Puzzel penetration methodology WFM penetration test summary Virtual Agent penetration test summary API penetration test summary View all Compliance ISO 27001 ISO 27701 SOC 2 Type 2 Cyber Essentials Monitoring Confidentiality Data Classification Policy A Data Classification Policy details the security and handling protocols for sensitive data. Network Security Network Security Policy A Network Security Policy identifies the requirements for protecting information and systems within and across networks. Risk Assessment Risk Register A risk register is maintained, which records the risk mitigation strategies for identified risks, and the development or modification of controls consistent with the risk mitigation strategy. Communications Privacy Policy A Privacy Policy to both external users and internal personnel. This policy details the company's privacy commitments. Terms of Service Terms of Service or the equivalent are published or shared to external users. Access Security Encryption and Key Management Policy An Encryption and Key Management Policy supports the secure encryption and decryption of app secrets, and governs the use of cryptographic controls. Incident Response Incident Response Plan An Incident Response Plan outlines the process of identifying, prioritizing, communicating, assigning and tracking confirmed incidents through to resolution. Tracking a Security Incident Identified incidents are documented, tracked, and analyzed according to the Incident Response Plan. Change Management Configuration and Asset Management Policy A Configuration and Asset Management Policy governs configurations for new sensitive systems Vulnerability Management Third-Party Penetration Test A 3rd party is engaged to conduct a network and application penetration test of the production environment at least annually. Critical and high-risk findings are tracked through resolution.