Third Party Index

Snapshot 70603

Document
Trust center
URL
https://trust.morae.com/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
428559 bytes
SHA-256 (raw)
4c2f144af033f051c1e2acb321a521e9778a3f70397a2a9265cfb02c3bc228ba
SHA-256 (normalized text)
6e3f73fdfc5a52e7fed6b7dd4fd05fabcbed5557952d51fa01616871b8f0c37b

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust Center
Start your security review
View & download sensitive information
Ask for information
Overview
Welcome to Morae Global's Trust Center.
At Morae Global, protecting the confidentiality, integrity, and availability of information is fundamental to how we operate. Security, privacy, and compliance are embedded throughout our people, processes, and technology, enabling us to deliver services our clients can trust.
This Trust Center provides transparency into our security and compliance programs, governance practices, and data protection measures. Here, you can learn more about our security posture, certifications, policies, and controls, as well as request access to relevant security documentation.
We are committed to maintaining the highest standards of information security and continuously enhancing our practices to safeguard the data entrusted to us.
Compliance
ISO/IEC 27001 SoA
SOC 2 Type 1
SOC 2 Type 2
Documents
REPORTSSOC 2 Report
REPORTSVulnerability Assessment Report
COMPLIANCEISO/IEC 27001 SoA
COMPLIANCESOC 2 Type 2
SELF-ASSESSMENTSISO27001
SELF-ASSESSMENTSSIG Lite
PRODUCT SECURITYData Security
PRODUCT SECURITYMulti-Factor Authentication
ENDPOINT SECURITYAnti-Malware
ENDPOINT SECURITYDisk Encryption
ENDPOINT SECURITYDNS Filtering
ENDPOINT SECURITYEndpoint Detection & Response
Risk Profile
Data Access LevelRestricted
Impact LevelSubstantial
Recovery Time Objective24-48 hours
Product Security
Data Security
Multi-Factor Authentication
Reports
Pentest Report
SOC 2 Report
Vulnerability Assessment Report
Self-Assessments
ISO27001
SIG Lite
Data Security
We follow industry best practices for data security. We are happy to provide more details about our data security practices upon request.
App Security
We take application security seriously and are putting together a program to monitor internal apps.
AI
We take the usage of AI seriously in our organization and work to ensure security and reliability of the AI.
ESG
We prioritize and take environmental, social, and governance (ESG) considerations seriously in our operations and decision-making processes.
Legal
We take legal matters seriously and we always engage our legal counsel to review all commercial activities. Please contact us if you have any questions.
Data Privacy
Privacy of customer data is top of mind. We follow industry best practices and follow all applicable privacy regulations.
Access Control
Access is tightly monitored and controlled at our company. We are happy to provide more details about our access control practices upon request.
Infrastructure
Data Center
Endpoint Security
Anti-Malware
Disk Encryption
DNS Filtering
View more
Network Security
Data Loss Prevention
Corporate Security
Email Protection
Employee Handbook
Employee Training
View more
Policies
Acceptable Use Policy
Access Control Policy
Asset Management Policy
View more
Security Grades
BitSight
Morae
740
Incident Response
Incident Reporting Process
Security Operations Center (SOC)
Risk Management
Risk Assessments
Asset Management
We have strict asset management policies in place to ensure that all assets are accounted for and secure.
BC/DR
Business Continuity Management System (BCMS)
Business Continuity Plan (BCP)
Disaster Recovery Plan (DRP)
View more
Training
Employee Privacy Training
Phishing Training
Role-Based Training
View more
Change Management
Change Advisory Board (CAB)
Change Control Board (CCB)
Change Management Program
View more
Physical & Environment
Access Monitoring
Physical Access Security
Visitor Control
Continuous Monitoring
Automated Alert Response
Data Loss Prevention System (DLP)
Security Information & Event Management (SIEM)
View more
Knowledge Base (FAQ)
Is the documented information required by the information security management system and by this document controlled to ensure it is adequately protected (e.g. from loss of confidentiality, improper use, or loss of integrity)?
Are any mobile devices with access to scoped data Constituent owned (BYOD)?
For all organizational entities (e.g., vendor's vendors, subcontractors, fourth parties, Nth parties) is there a contractual relationship that extends obligations to each entity?
Is there a records retention policy and retention schedule covering paper and electronic records, including email in support of applicable regulations, standards, and contractual requirements?
Is there an DMZ environment within the network that transmits, processes, or stores scoped systems and data e.g., web servers, DNS, directory services, remote access, etc.?
View more