Controls for

Pro

A focused reading path for teams evaluating Dapta independently.

Filtered control register
29
Review context
Self-service

The SOC 2 report covers the Dapta Platform. Plan labels do not change report scope.

Infrastructure security

21 controls listed
Unique production database authentication enforcedProduction datastores require approved secure authentication, such as a unique SSH key.Access and authentication boundariesNetwork and platform safeguards
Encryption key access restrictedPrivileged access to encryption keys is limited to authorized users with a business need.Access and authentication boundariesNetwork and platform safeguards
Unique account authentication enforcedSystems and applications require unique credentials or approved SSH keys.Access and authentication boundariesNetwork and platform safeguards
Production application access restrictedProduction application access is restricted to authorized users.Access and authentication boundariesNetwork and platform safeguards
Access control procedures establishedDocumented procedures govern adding, modifying, and removing user access.Access and authentication boundariesNetwork and platform safeguards
Production database access restrictedPrivileged production database access is limited to authorized users with a business need.Access and authentication boundariesNetwork and platform safeguards
Firewall access restrictedPrivileged firewall access is limited to authorized users with a business need.Access and authentication boundariesNetwork and platform safeguards
Production OS access restrictedPrivileged production operating-system access is limited to authorized users with a business need.Access and authentication boundariesNetwork and platform safeguards
Production network access restrictedPrivileged production-network access is limited to authorized users with a business need.Access and authentication boundariesNetwork and platform safeguards
Access revoked upon terminationTermination checklists are used to revoke former employees' access within defined timelines.Access and authentication boundariesNetwork and platform safeguards
Unique network system authentication enforcedProduction-network authentication requires unique credentials or approved SSH keys.Access and authentication boundariesNetwork and platform safeguards
Remote access MFA enforcedRemote production access is limited to authorized employees using multi-factor authentication.Access and authentication boundariesNetwork and platform safeguards
Remote access encryption enforcedRemote production access requires an approved encrypted connection.Access and authentication boundariesNetwork and platform safeguards
Intrusion detection system utilizedNetwork monitoring is used to detect potential security breaches early.Access and authentication boundariesNetwork and platform safeguards
Log management utilizedLog management helps identify events that could affect security objectives.Access and authentication boundariesNetwork and platform safeguards
Infrastructure performance monitoredInfrastructure and performance monitoring generates alerts at predefined thresholds.Access and authentication boundariesNetwork and platform safeguards
Network segmentation implementedNetwork segmentation is used to prevent unauthorized access to customer data.Access and authentication boundariesNetwork and platform safeguards
Network firewalls reviewedFirewall rules are reviewed at least annually and required changes are tracked.Access and authentication boundariesNetwork and platform safeguards
Network firewalls utilizedFirewalls are configured to help prevent unauthorized access.Access and authentication boundariesNetwork and platform safeguards
Network and system hardening standards maintainedDocumented hardening standards follow industry practices and are reviewed at least annually.Access and authentication boundariesNetwork and platform safeguards
Service infrastructure maintainedService infrastructure is patched through routine maintenance and vulnerability remediation.Access and authentication boundariesNetwork and platform safeguards

Product security

5 controls listed
Data encryption utilizedDatastores containing sensitive customer data are encrypted at rest.Encryption and assurance testingProduct security operations
Control self-assessments conductedControls are self-assessed at least annually and corrective actions are tracked against applicable timelines.Encryption and assurance testingProduct security operations
Penetration testing performedPenetration tests are performed at least annually and findings are remediated through tracked plans.Encryption and assurance testingProduct security operations
Data transmission encryptedSecure transmission protocols encrypt confidential and sensitive data over public networks.Encryption and assurance testingProduct security operations
Vulnerability and system monitoring procedures establishedFormal policies define vulnerability-management and system-monitoring requirements.Encryption and assurance testingProduct security operations

Data and privacy

3 controls listed
Data retention procedures establishedFormal procedures guide secure retention and disposal of company and customer data.Retention and deletionData classification and handling
Customer data deleted upon leavingConfidential customer data is removed from the application environment when service ends.Retention and deletionData classification and handling
Data classification policy establishedA classification policy supports appropriate protection and restricted access for confidential data.Retention and deletionData classification and handling