SOC 2 Type 2 Report - 2025
November 1, 2024 - January 31, 2025
Our security, compliance, and policy documentation, including audit reports.
November 1, 2024 - January 31, 2025
October 21, 2024
February 1st, 2025 - January 31st, 2026
October 30, 2025
Describes how user access to systems and data is provisioned, reviewed, and revoked based on roles and business needs, following the principle of least privilege.
Provides guidance for identifying, classifying, and protecting company-owned assets, ensuring they are tracked, maintained, and security handled throughout their lifecycle.
Establishes plans for maintaining operations during outages or crises, and outlines recovery procedures to restore systems and services with minimal disruption.
Defines acceptable behaviors and responsibilities for all employees to ensure a respectful and inclusive workplace.
Describes how data is classified, handled, and protected throughout its lifecycle, ensuring compliance with legal and regulatory requirements.
Establishes a framework for managing risks to the organization's operations, assets, and individuals.
Outlines how the organization detects, reports, investigates, and responds to security incidents to minimize impact and support recovery and compliance obligations.
Establishes the framework for managing and protecting sensitive information assets, ensuring confidentiality, integrity, and availability.
Defines the security measures and protocols for monitoring, detecting, and responding to security incidents within the organization's IT environment.
Establishes guidelines for secure software development practices, including coding standards, code reviews, and security testing.
Establishes a framework for managing risks associated with third-party vendors, including risk assessment, due diligence, and ongoing monitoring.