SOC 2 Type II Report - 2025
No description available.
Our security, compliance, and policy documentation, including audit reports.
No description available.
No description available.
No description available.
Establishes plans for maintaining operations during outages or crises, and outlines recovery procedures to restore systems and services with minimal disruption.
Establishes the framework for managing and protecting sensitive information assets, ensuring confidentiality, integrity, and availability.
Outlines how the organization detects, reports, investigates, and responds to security incidents to minimize impact and support recovery and compliance obligations.
Defines the roles and responsibilities for information security within the organization, ensuring accountability and effective management of security risks.
Defines acceptable behaviors and responsibilities for all employees to ensure a respectful and inclusive workplace.
Describes how user access to systems and data is provisioned, reviewed, and revoked based on roles and business needs, following the principle of least privilege.
Establishes a framework for managing risks to the organization's operations, assets, and individuals.
Establishes guidelines for secure software development practices, including coding standards, code reviews, and security testing.
Establishes a framework for managing risks associated with third-party vendors, including risk assessment, due diligence, and ongoing monitoring.
This standard documents the control objectives, technical configurations, and operational procedures used to implement and maintain compliance with PCI DSS.
This Artificial Intelligence Management Policy (the “Policy”) establishes the Artificial Intelligence Management System (the “AIMS”) for products designed, created and implemented by Deck that use artificial intelligence.
This policy specifies acceptable use of end-user computing devices and technology.