REQOPS
Security · 03 · Compliance

Compliance and assurance.

SOC 2 Type II, ISO 27001, GDPR, and annual penetration testing — what each element covers, and the documentation available for each.

SOC 2TYPE II
Report under NDA
ISO27001
Certified ISMS
GDPRCOMPLIANT
DPA + SCCs ready
PENTESTANNUAL
Retest attestation
The assurance program

The four elements of the program.

STEP 01

The baseline, built in from day one

Before anyone external is paid: single sign-on ready authentication, least-privilege roles, hardened APIs, encrypted stores, an append-only audit trail, kill switches, and a scanned supply chain. External validation tests this — it doesn't replace it.

proof: the baseline checklist, ticked and dated
STEP 02

Penetration testing, every year

Independent testers, a written scope, full coverage of the application and its APIs — then every finding fixed within a defined service level and retested. Repeated annually and after major changes.

proof: retest attestation lettersummary shareable under NDA
STEP 03

SOC 2 Type II — audited over time

A Type II audit examines months of actual operation — access reviews, restore tests, closed alerts, incident drills — not a binder assembled the month before. The controls run continuously and the evidence is dated as it happens.

proof: SOC 2 Type II report, under NDA
STEP 04

ISO 27001 — the certified management system

The risk register, policy set and operating habits run as a certified information security management system — the certificate common in government and EU enterprise reviews, backed by the same evidence as everything else on these pages.

proof: certificate + statement of applicability
AI

AI security.

How AI usage is governed, documented, and controlled.

What uses AIwritten down
An AI transparency statement lists every feature that calls a model, what data reaches it, and what never does.
Your data, their modelsthe training question
Customer data is not used to train models. That commitment is contractual, and the model vendors we use are held to it in writing.
Attackstested like any other
AI features are tested against the known attack list for language models — prompt injection, data leakage, poisoned outputs — and successful attempts become permanent regression tests.
Oversighthumans decide
AI drafts, suggests and flags — people approve. And every AI feature sits behind its own kill switch, so the product runs even with the model off.
Vendors

Vendor management.

Tiered vettingeffort where the risk is
Vendors that touch customer data get full due diligence — security reports, DPAs, breach history — before use. Low-risk tools get a proportionate check. Every decision is recorded.
One file per vendorreviewed on schedule
Each vendor has a file: what they access, what we checked, when it was last reviewed. The critical ones are re-checked quarterly, the rest annually.
Flow-downyour protections travel
The commitments we make to you — confidentiality, breach notice, deletion — are written into our contracts with them. Your protections don't stop at our edge.
FOR YOUR REVIEWUNDER NDA

Your security team can request the full pack at any stage of evaluation: the pentest attestation and summary, the policy set, the risk register, diagrams, the DPA, and the evidence behind any claim on these pages.

Questionnaires are answered from the same document set, with the source document named per answer.

Request documentation.

Send a questionnaire, arrange a walkthrough, or request a specific document.