Compliances

Compliance Logo

SOC 2

Compliant

Compliance Logo

ISO 27001

In progress

Trusted by

Trusted By Company Logo
Trusted By Company Logo

Controls

Product security

Entity ensures that critical Cloud Service Providers can enforce the password management requirements defined by the Entity

Entity ensures that encryption controls available with critical Cloud Service Providers are assessed and implemented as per the Encryption Policy

Entity ensures that critical Cloud Service Providers are capable to dispose or reuse resources in accordance with the Entity's disposal and reuse requirements

Data security

The Entity ensures that all software installed on cloud solutions is appropriately licensed

Entity maintains a matrix that outlines which system components should be accessible to staff members based on their role.

Staff access to Entity's systems are made inaccessible in a timely manner as a part of the offboarding process.

Network security

Entity ensures that customer data used in non-Production environments requires the same level of protection as the production environment

The entity systems generate information that is reviewed and evaluated to determine impacts to the functioning of internal controls.

The Entity acquires information on the time service provider used by critical Cloud Service Providers

App security

Entity uses Sprinto, a continuous monitoring system, to alert the security team to update the access levels of team members whose roles have changed

Entity displays the most current information about its services on its website, which is accessible to its customers.

Entity uses a change management system to track, review and log all changes to the application code.

Endpoint security

Entity requires that all critical endpoints are encrypted to protect them from unauthorised access

Entity requires that all endpoints with access to production systems are protected by malware-protection software

Entity requires that all company-owned endpoints be encrypted to protect them from unauthorised access

Corporate security

Entity has established behavioral standards which are defined in the Code of Business Conduct and makes it available to all staff members on the company employee portal

Entity appoints a Privacy Officer to assess and facilitate the entity's compliance with relevant regulatory requirements

Entity requires that all staff members review and acknowledge company policies annually

Resources

test

Policy

2test

Policy

test for document

Document

test dummy

Document

Subprocessors

Subprocessor Logo

customww fw rdf

hello sss wefwerwef

Albania

Subprocessor Logo

Okta

Identity Providers

Afghanistan

Subprocessor Logo

Office365

Identity Providers

Algeria

Subprocessor Logo

Zoho

Identity Providers

Andorra

Subprocessor Logo

AWS

Cloud Providers

United States of America

Subprocessor Logo

Whatsapp

whatsapp

American Samoa

Updates

update 1

Apr 3, 2025

FAQ