Compliance and assurance.
SOC 2 Type II, ISO 27001, GDPR, and annual penetration testing — what each element covers, and the documentation available for each.
The four elements of the program.
The baseline, built in from day one
Before anyone external is paid: single sign-on ready authentication, least-privilege roles, hardened APIs, encrypted stores, an append-only audit trail, kill switches, and a scanned supply chain. External validation tests this — it doesn't replace it.
Penetration testing, every year
Independent testers, a written scope, full coverage of the application and its APIs — then every finding fixed within a defined service level and retested. Repeated annually and after major changes.
SOC 2 Type II — audited over time
A Type II audit examines months of actual operation — access reviews, restore tests, closed alerts, incident drills — not a binder assembled the month before. The controls run continuously and the evidence is dated as it happens.
ISO 27001 — the certified management system
The risk register, policy set and operating habits run as a certified information security management system — the certificate common in government and EU enterprise reviews, backed by the same evidence as everything else on these pages.
AI security.
How AI usage is governed, documented, and controlled.
Vendor management.
Your security team can request the full pack at any stage of evaluation: the pentest attestation and summary, the policy set, the risk register, diagrams, the DPA, and the evidence behind any claim on these pages.
Questionnaires are answered from the same document set, with the source document named per answer.
Send a questionnaire, arrange a walkthrough, or request a specific document.