Unique production database authentication enforcedProduction datastores require approved secure authentication, such as a unique SSH key.Access and authentication boundariesNetwork and platform safeguards
Controls for
Scale Up, Prime & Enterprise
A governance-oriented reading path for larger or more complex evaluations.
The SOC 2 report covers the Dapta Platform. Plan labels do not change report scope.
Infrastructure security
21 controls listedEncryption key access restrictedPrivileged access to encryption keys is limited to authorized users with a business need.Access and authentication boundariesNetwork and platform safeguards
Unique account authentication enforcedSystems and applications require unique credentials or approved SSH keys.Access and authentication boundariesNetwork and platform safeguards
Production application access restrictedProduction application access is restricted to authorized users.Access and authentication boundariesNetwork and platform safeguards
Access control procedures establishedDocumented procedures govern adding, modifying, and removing user access.Access and authentication boundariesNetwork and platform safeguards
Production database access restrictedPrivileged production database access is limited to authorized users with a business need.Access and authentication boundariesNetwork and platform safeguards
Firewall access restrictedPrivileged firewall access is limited to authorized users with a business need.Access and authentication boundariesNetwork and platform safeguards
Production OS access restrictedPrivileged production operating-system access is limited to authorized users with a business need.Access and authentication boundariesNetwork and platform safeguards
Production network access restrictedPrivileged production-network access is limited to authorized users with a business need.Access and authentication boundariesNetwork and platform safeguards
Access revoked upon terminationTermination checklists are used to revoke former employees' access within defined timelines.Access and authentication boundariesNetwork and platform safeguards
Unique network system authentication enforcedProduction-network authentication requires unique credentials or approved SSH keys.Access and authentication boundariesNetwork and platform safeguards
Remote access MFA enforcedRemote production access is limited to authorized employees using multi-factor authentication.Access and authentication boundariesNetwork and platform safeguards
Remote access encryption enforcedRemote production access requires an approved encrypted connection.Access and authentication boundariesNetwork and platform safeguards
Intrusion detection system utilizedNetwork monitoring is used to detect potential security breaches early.Access and authentication boundariesNetwork and platform safeguards
Log management utilizedLog management helps identify events that could affect security objectives.Access and authentication boundariesNetwork and platform safeguards
Infrastructure performance monitoredInfrastructure and performance monitoring generates alerts at predefined thresholds.Access and authentication boundariesNetwork and platform safeguards
Network segmentation implementedNetwork segmentation is used to prevent unauthorized access to customer data.Access and authentication boundariesNetwork and platform safeguards
Network firewalls reviewedFirewall rules are reviewed at least annually and required changes are tracked.Access and authentication boundariesNetwork and platform safeguards
Network firewalls utilizedFirewalls are configured to help prevent unauthorized access.Access and authentication boundariesNetwork and platform safeguards
Network and system hardening standards maintainedDocumented hardening standards follow industry practices and are reviewed at least annually.Access and authentication boundariesNetwork and platform safeguards
Service infrastructure maintainedService infrastructure is patched through routine maintenance and vulnerability remediation.Access and authentication boundariesNetwork and platform safeguards
Organizational security
13 controls listedAsset disposal procedures utilizedElectronic media with confidential information is securely purged or destroyed, with destruction documented.People and asset safeguardsPolicy enforcement
Production inventory maintainedA formal inventory of production-system assets is maintained.People and asset safeguardsPolicy enforcement
Anti-malware technology utilizedAnti-malware protection is deployed, updated, and logged on relevant systems.People and asset safeguardsPolicy enforcement
Employee background checks performedBackground checks are performed for new employees.People and asset safeguardsPolicy enforcement
Code of Conduct acknowledged by contractorsContractor agreements include or reference the company code of conduct.People and asset safeguardsPolicy enforcement
Code of Conduct acknowledged by employees and enforcedEmployees acknowledge the code of conduct at hiring, and violations are subject to discipline.People and asset safeguardsPolicy enforcement
Confidentiality Agreement acknowledged by contractorsContractors sign a confidentiality agreement when their engagement begins.People and asset safeguardsPolicy enforcement
Confidentiality Agreement acknowledged by employeesEmployees sign a confidentiality agreement during onboarding.People and asset safeguardsPolicy enforcement
Performance evaluations conductedManagers complete performance evaluations for direct reports at least annually.People and asset safeguardsPolicy enforcement
Password policy enforcedPasswords for in-scope systems are configured according to company policy.People and asset safeguardsPolicy enforcement
MDM system utilizedA mobile-device management system centrally manages devices supporting the service.People and asset safeguardsPolicy enforcement
Visitor procedures enforcedVisitors sign in, wear identification, and are escorted in secure areas.People and asset safeguardsPolicy enforcement
Security awareness training implementedEmployees complete security awareness training after hiring and at least annually thereafter.People and asset safeguardsPolicy enforcement
Product security
5 controls listedData encryption utilizedDatastores containing sensitive customer data are encrypted at rest.Encryption and assurance testingProduct security operations
Control self-assessments conductedControls are self-assessed at least annually and corrective actions are tracked against applicable timelines.Encryption and assurance testingProduct security operations
Penetration testing performedPenetration tests are performed at least annually and findings are remediated through tracked plans.Encryption and assurance testingProduct security operations
Data transmission encryptedSecure transmission protocols encrypt confidential and sensitive data over public networks.Encryption and assurance testingProduct security operations
Vulnerability and system monitoring procedures establishedFormal policies define vulnerability-management and system-monitoring requirements.Encryption and assurance testingProduct security operations
Internal security procedures
37 controls listedContinuity and Disaster Recovery plans establishedBusiness continuity and disaster-recovery plans include communications for key-personnel unavailability.Governance processOperating cadence and evidence
Continuity and Disaster Recovery plans testedDocumented business-continuity and disaster-recovery plans are tested at least annually.Governance processOperating cadence and evidence
Cybersecurity insurance maintainedCybersecurity insurance is maintained to mitigate the financial impact of disruptions.Governance processOperating cadence and evidence
Configuration management system establishedConfiguration-management procedures support consistent system deployment.Governance processOperating cadence and evidence
Change management procedures enforcedSoftware and infrastructure changes are authorized, documented, tested, reviewed, and approved before production.Governance processOperating cadence and evidence
Production deployment access restrictedOnly authorized personnel can migrate changes into production.Governance processOperating cadence and evidence
Development lifecycle establishedA formal SDLC governs development, acquisition, implementation, change, and maintenance.Governance processOperating cadence and evidence
SOC 2 — System DescriptionA system description is prepared for Section III of the SOC 2 audit report.Governance processOperating cadence and evidence
Whistleblower policy establishedA formal whistleblower policy and anonymous reporting channel are maintained.Governance processOperating cadence and evidence
Board oversight briefings conductedSenior management briefs the board on cybersecurity and privacy risk at least annually.Governance processOperating cadence and evidence
Board charter documentedThe board charter documents oversight responsibilities for internal control.Governance processOperating cadence and evidence
Board expertise developedBoard members maintain relevant oversight expertise and engage security specialists when needed.Governance processOperating cadence and evidence
Board meetings conductedThe board meets at least annually, keeps minutes, and includes independent directors.Governance processOperating cadence and evidence
Backup processes establishedThe data-backup policy defines requirements for backup and customer-data recovery.Governance processOperating cadence and evidence
System changes externally communicatedCustomers are notified of critical system changes that may affect their processing.Governance processOperating cadence and evidence
Management roles and responsibilities definedManagement defines responsibility for security-control design and implementation.Governance processOperating cadence and evidence
Organization structure documentedAn organizational chart documents structure and reporting lines.Governance processOperating cadence and evidence
Roles and responsibilities specifiedSecurity-control responsibilities are formally assigned through role documentation.Governance processOperating cadence and evidence
Support system availableAn external support channel lets users report failures, incidents, concerns, and complaints.Governance processOperating cadence and evidence
System changes communicatedSystem changes are communicated to authorized internal users.Governance processOperating cadence and evidence
Access reviews conductedAccess to in-scope systems is reviewed at least quarterly and required changes are tracked.Governance processOperating cadence and evidence
Access requests requiredAccess is role-based or requires a documented request and management approval.Governance processOperating cadence and evidence
Incident response plan testedThe incident-response plan is tested at least annually.Governance processOperating cadence and evidence
Incident response policies establishedSecurity and privacy incident-response policies are documented and communicated.Governance processOperating cadence and evidence
Incident management procedures followedSecurity and privacy incidents are logged, tracked, resolved, and communicated under documented procedures.Governance processOperating cadence and evidence
Physical access processes establishedPhysical data-center access is granted, changed, and terminated through authorized processes.Governance processOperating cadence and evidence
Data center access reviewedData-center access is reviewed at least annually.Governance processOperating cadence and evidence
Company commitments externally communicatedSecurity commitments are communicated through customer agreements or terms of service.Governance processOperating cadence and evidence
External support resources availableCustomers receive guidance and technical-support resources for system operations.Governance processOperating cadence and evidence
Service description communicatedProduct and service descriptions are provided to internal and external users.Governance processOperating cadence and evidence
Risk assessment objectives specifiedObjectives are defined so related risks can be identified and assessed.Governance processOperating cadence and evidence
Risk assessments performedRisk assessments are performed at least annually and consider threats, change, and fraud potential.Governance processOperating cadence and evidence
Risk management program establishedA documented program guides threat identification, risk rating, and mitigation strategies.Governance processOperating cadence and evidence
Third-party agreements establishedWritten vendor agreements include applicable confidentiality and privacy commitments.Governance processOperating cadence and evidence
Vendor management program establishedThe vendor program maintains critical-provider inventory, security requirements, and annual reviews.Governance processOperating cadence and evidence
Vulnerabilities scanned and remediatedExternal-facing systems receive quarterly host scans and high-priority findings are tracked to remediation.Governance processOperating cadence and evidence
Security policies established and reviewedInformation-security policies and procedures are documented and reviewed at least annually.Governance processOperating cadence and evidence
Data and privacy
3 controls listedData retention procedures establishedFormal procedures guide secure retention and disposal of company and customer data.Retention and deletionData classification and handling
Customer data deleted upon leavingConfidential customer data is removed from the application environment when service ends.Retention and deletionData classification and handling
Data classification policy establishedA classification policy supports appropriate protection and restricted access for confidential data.Retention and deletionData classification and handling
