Security and trust at SaaSAudit

Our security program is audited by third-party assessors and continuously monitored.

[email protected]Privacy PolicyAWS Marketplace Listing

Compliance

Independently audited against leading security frameworks.

SOC
AICPA
SOC 2
Compliant
Active

Controls

Real-time evidence from 95 active controls.

Policy
Code of Conduct Policy Defined
Information Security Policy Established
Quarterly Vulnerability Scans Performed
+ 19 more
Security Policies Established and Annually Reviewed
The entity has established all required security policies, which are reviewed and approved by senior management on at least an annual basis.
Passing
Responsible Disclosure Process Defined
The entity has defined and communicated a responsible disclosure process to enable employees and external parties to report security vulnerabilities.
Passing
Incident Response Plan Established
The entity has established a documented incident response plan that defines procedures for detecting, containing, remediating, and communicating security incidents.
Passing
Incident Response Team Established
The entity has established a designated incident response team with defined roles, responsibilities, and escalation procedures.
Passing
Risk Management Policy Established
The entity has established a formal risk management policy that defines the risk management framework, methodology, and risk appetite.
Passing
Change Management Process Established
The entity has established a formal change management process to authorise, document, test, and approve changes to infrastructure, software, and procedures.
Passing
Access Control Policy Defined
The entity has defined an access control policy that establishes the principles of least privilege, role-based access, and system access authorisation requirements.
Passing
Password Policy Defined for Authentication
The entity has defined password complexity, length, rotation, and reuse requirements to govern authentication credentials across all systems.
Passing
Encryption Key Management Process Established
The entity has established a formal encryption key management process covering key generation, distribution, rotation, and revocation.
Passing
Employee Termination and Offboarding Checklist Maintained
The entity maintains a formal termination/offboarding checklist to ensure all access is revoked, equipment is returned, and confidential data is secured upon employee departure.
Passing
Physical Security Policy Established
The entity has established and maintains a physical security policy that governs access to facilities, equipment, and sensitive locations.
Passing
Data Deletion Policy Established
The entity has established a data deletion policy that defines retention periods and procedures for the secure disposal of data in compliance with regulatory requirements.
Passing
Data Retention Policy Established
The entity has established a data retention policy that defines minimum and maximum retention periods for all data classifications.
Passing
Business Continuity / Disaster Recovery Plan Established
The entity has established a documented business continuity and disaster recovery plan that defines recovery objectives, procedures, and responsibilities.
Passing
Data Backup Policy Defined
The entity has defined a data backup policy specifying backup frequency, retention periods, and recovery objectives.
Passing
Software Development Lifecycle (SDLC) Policy Defined
The entity has defined an SDLC policy that governs the design, development, testing, deployment, and maintenance of software.
Passing
Data Classification Policy Established
The entity has established a data classification policy that categorises data by sensitivity and defines handling requirements for each classification level.
Passing
Clean Desk Policy Established
The entity has established a clean desk policy requiring employees to secure sensitive materials and lock screens when workstations are unattended.
Passing
Data Protection Policy Established
The entity has established a comprehensive data protection policy that governs the collection, processing, storage, and disposal of personal and sensitive data.
Passing
HR
Code of Conduct Acknowledgement Mandated
Confidentiality Agreement Acknowledgement Mandated
Organisational Chart Maintained
+ 7 more
Job Descriptions Maintained for Open Positions
The entity provides clear job descriptions for open positions to attract qualified candidates aligned with security and competency requirements.
Passing
Pre-Employment Background Checks Conducted
The entity requires and completes background checks for all new hires prior to granting access to systems and data.
Passing
Formal Employment Agreement Required
The entity requires all new hires to sign a formal employment agreement prior to commencement of employment.
Passing
Annual Employee Performance Evaluations Conducted
The entity conducts annual performance evaluations for all employees to assess competency and accountability.
Passing
Annual Security Awareness Training Mandated
The entity mandates annual information security awareness training for all employees and contractors to maintain security competency.
Passing
Employee Policy Acknowledgement Required
The entity requires all employees to formally acknowledge all applicable company policies on an annual basis.
Passing
System Access Revoked Upon Termination Within SLA
The entity revokes all logical and physical access for terminated employees and contractors within the defined offboarding SLA.
Passing
Company
Independent Board of Directors with Appropriate Expertise
Board Charter Documented
Board Oversight Briefing Meetings Conducted
+ 3 more
Security Commitments Communicated to Customers
The entity communicates its security commitments, including commitments set forth in customer agreements (MSAs), to all relevant external parties.
Passing
Product/Service Description Publicly Available
The entity makes a clear description of its products and services publicly available to inform customers and stakeholders.
Passing
Cybersecurity Insurance Maintained
The entity maintains cybersecurity liability insurance to mitigate financial exposure from security incidents and data breaches.
Passing
IT/Security
Key InfoSec Roles Defined and Assigned
Security Team / Steering Committee Established
Control Self-Assessments Conducted Annually
+ 8 more
Security Events Communicated to Senior Management
The entity's incident response team communicates all material security events to senior management in a timely manner.
Passing
Customers Informed of Material System Changes
The entity communicates material system changes and service updates to customers in a timely and transparent manner.
Passing
Customer Support System Established
The entity has established an accessible customer support system with published contact information to address customer enquiries and issues.
Passing
Annual Penetration Testing Performed
The entity engages qualified third parties to perform penetration testing on at least an annual basis to identify and remediate security vulnerabilities.
Passing
Annual Access Control Reviews Performed
The entity performs formal access control reviews on at least an annual basis to ensure access privileges remain appropriate and aligned with current roles.
Passing
Formal Access Requests with Role-Based Access Controls
The entity requires formal access requests with documented approval for all access to critical systems, applying role-based access controls consistent with the principle of least privilege.
Passing
Test Data Used in Non-Production Environments
The entity enforces the use of non-production / anonymised test data in all testing and development environments to protect customer data.
Passing
Customer Data Deleted Upon Contract Termination
The entity ensures customer data is securely deleted upon contract termination in accordance with contractual obligations and data retention policies.
Passing
Asset Inventory
Comprehensive Asset Inventory Maintained
Infrastructure
Network Architecture Diagram Maintained
Passwords Stored Using Salted Hashing
No Orphan Accounts in Systems
+ 5 more
SSL/TLS Encryption Enforced
The entity enforces TLS 1.2 or higher for all data in transit and rejects connections using deprecated SSL/TLS versions.
Passing
Inactivity Logout Implemented in Applications
The entity's applications automatically terminate user sessions upon inactivity or browser exit to prevent unauthorised access.
Passing
Customer Data Logically Segregated
The entity implements logical segregation to ensure customer data is isolated and inaccessible across tenant boundaries.
Passing
Root / Privileged Account Login Restricted
The entity restricts root account usage in cloud infrastructure, ensuring the root account has not been used for console login within the last 30 days.
Passing
Quarterly Processing Capacity and Usage Review
The entity conducts quarterly reviews of processing capacity and system usage to ensure adequate resources are available to meet service commitments.
Passing
Risk
Annual Risk Assessments Performed
Vendors
Vendor Management Policy Established
Vendor Agreements and Criticality Ratings Maintained
Annual Vendor Compliance Reviews Performed
Device
Asset Disposal Procedures Implemented
Screen Lock Enforced on Company Devices
Removable Media Encryption Required
+ 2 more
Full Disk Encryption Required on Company Devices
The entity requires full disk encryption on all company-managed devices using industry-standard technologies (FileVault, BitLocker, LUKS).
Passing
Anti-Malware Technology Deployed on Endpoints
The entity has deployed anti-malware / endpoint detection and response (EDR) technology on all company-managed devices.
Passing
Software Development
Version Control and CI/CD Pipeline Established
Code Changes Reviewed and Approved Prior to Deployment
Security Issues Tracked and Prioritised
+ 7 more
Changes Tested Prior to Production Deployment
The entity requires all changes to be tested in a non-production environment and validated prior to deployment to production.
Passing
Production Code Changes Restricted to Authorised Personnel
The entity restricts write access to production branches and deployment pipelines to a defined set of authorised personnel.
Passing
Production Releases Require Authorised Approval
The entity requires formal approval from designated authorised personnel before any code release is deployed to production.
Passing
Input Validation Controls Implemented
The entity's applications enforce input validation controls, including range checks and format validation, to prevent processing of invalid data.
Passing
Mandatory Field Validation Enforced
The entity's applications enforce mandatory field validation to ensure all required data is provided before processing transactions.
Passing
Regression Testing Conducted Prior to Release
The entity performs regression testing prior to each production release to verify that existing functionality is not adversely affected by changes.
Passing
Performance Testing Conducted to Validate SLA Compliance
The entity conducts performance testing to verify that applications meet defined service level agreements under expected load conditions.
Passing
Incident Response
Annual Incident Response Review Performed
Incident Reports Include Root Cause Analysis and Lessons Learnt
Disaster Recovery
BC/DR Plan Tested Annually
Backup Integrity and Completeness Verified
Privacy
Privacy Policy Publicly Available
Privacy Notice Provided and Explicit Consent Obtained
Privacy Practices Reviewed Annually
+ 11 more
Minimal Personal Information Collected
The entity collects only the minimum personal information necessary to fulfil the stated business purpose, consistent with data minimisation principles.
Passing
Data Subject Deletion Requests Honoured
The entity processes and fulfils verified data subject requests for deletion of personal information within the required timeframe.
Passing
Identity Authenticated Before Granting Personal Data Access
The entity verifies the identity of data subjects before granting access to or disclosing their personal information.
Passing
Data Access Requests Fulfilled for Data Subjects
The entity processes and fulfils verified data access requests from data subjects, providing copies of personal information held upon request.
Passing
Personal Data Modification Requests Processed
The entity corrects or amends personal information based on verified requests from data subjects within the required timeframe.
Passing
Data Processing Agreements in Place for PI Vendors
The entity ensures all vendors processing Personal Information on its behalf have executed a Data Processing Agreement (DPA) that defines data handling obligations.
Passing
PII Data Breaches Tracked and Documented
The entity maintains a formal register to track all actual and suspected breaches of Personally Identifiable Information (PII), including investigation status and remediation actions.
Passing
Business Associate Agreements in Place for PHI Vendors
The entity ensures all vendors processing Protected Health Information (PHI) have executed a Business Associate Agreement (BAA) in compliance with HIPAA requirements.
Passing
Vendors Instructed on Data Breach Reporting for PI Data
The entity provides all vendors handling Personal Information with clear instructions on how to identify and report actual or suspected data breaches.
Passing
Data Breach Notification Process Established
The entity has established a formal data breach notification process that defines procedures for notifying affected data subjects, regulators, and other required parties within statutory timeframes.
Passing
Privacy Contact Information Publicly Available
The entity provides publicly accessible contact information for privacy-related enquiries, complaints, and dispute resolution.
Passing

Resources

Download or request access to our security artifacts.

SOC 2 Type 1 Report
PDF · 6.0 MB · Requires NDA

Subprocessors

Third parties that process customer data on our behalf.

GitHub
Software Development
Microsoft Azure
Cloud Services
Microsoft Entra
Identity and Access Management
Aikido Security
Security Monitoring
Apollo
Sales Engagement
Atlassian
Project Management
HubSpot
CRM
Need something specific?
Our team responds to security review requests within 1 business day.