Do you meet SOC 2 and ISO 27001 requirements?
Yes. We are ISO 27001 certified covering access control, secret management, audit trails, incident response, and physical security. For SOC 2 engagements we operate within the client's SOC 2 boundary using their controls, evidence collection, and audit trail. We provide vendor security questionnaire responses, data flow diagrams, sub processor lists, and infrastructure documentation that audit teams typically require. We have worked through full SOC 2 Type II audits with multiple clients including a US healthcare client and a UK fintech.