Live Trust Centerdemo's compliance, in the open.
Real-time posture, continuously monitored with signed, RFC-3161 timestamped, tamper-evident evidence - every control independently verifiable.
34of 90 controls passing
Continuously monitored across 7 frameworks. Evidence is signed, timestamped, and hash-chained.
Get in touch
Need the SOC 2 report, a pen-test summary, or to talk to the team? Request access and they will follow up.
Agreements & legal
BAA available
Business Associate Agreement (HIPAA)
DPA available
Data Processing Agreement (GDPR), with SCCs
Subprocessor list available
Current subprocessors and their assurance
Frameworks
SOC 2 (Trust Services Criteria)
33 criteria
HIPAA Security Rule
Not in scope
ISO/IEC 27001:2022 (Annex A)
Not in scope
ISO/IEC 42001:2023 (AI management)
Not in scope
NIST AI RMF 1.0
Not in scope
EU AI Act (Regulation 2024/1689)
Not in scope
Monitored controls (90)
Passing Failing Pending
- Encryption at rest (KMS)
- TLS for data in transit
- AWS Config continuous recording
- Security Hub finding aggregation
- GuardDuty threat detection
- IAM access keys rotated
- Unused credentials disabled
- IAM Access Analyzer enabled
- CloudTrail log-file validation
- CloudTrail encrypted with KMS
- VPC flow logs enabled
- S3 default encryption
- RDS encrypted at rest
- AI usage logged to the signed evidence ledger
- Disciplinary process for policy violations
- KMS key rotation enabled
- AWS Backup plan configured
- Security tickets are assigned
- Ticketed change management
- Onboarding and offboarding
- Quarterly access reviews
- Incident response plan
- Policy documents match their approved version
- Code of conduct acknowledged by personnel
- Organizational structure and reporting lines defined
- Security roles and responsibilities documented
- Job descriptions define required competencies
- Performance reviews hold personnel accountable
- Confidentiality agreements signed
- Security policies published to personnel
- External vulnerability disclosure channel
- Annual enterprise risk assessment
- Security awareness training
- Fraud risk considered in assessment
- Significant changes assessed for risk
- Ongoing monitoring of control effectiveness
- Independent internal control review
- Subservice organization SOC reports reviewed
- Control activities mapped to risks
- Policies reviewed and approved annually
- Secure disposal of data and media
- Endpoint anti-malware protection
- Security incidents contained and responded to
- Incident recovery and post-incident review
- Breach notification process
- Business continuity plan maintained
- Backups performed and restoration tested
- Cyber insurance coverage maintained
- Vendors risk-assessed before engagement
- Vendor and subprocessor inventory maintained
- Vendor contracts include security terms
- Internal channel for reporting security concerns
- No stale Okta accounts
- Segregation of duties enforced
- Disaster recovery exercise performed
- AI gateway enforces data-loss protection
- People are told when they are interacting with AI
- Prompt injection monitored at the AI gateway
- Deepfakes and AI-authored public-interest text are disclosed
- Audit logging enabled
- Vulnerability scanning in place
- Background checks performed
- Least-privilege access
- Change management and code review
- Network access segmented
- Strong IAM password policy
- Root account hardened
- EBS default encryption
- Managed device security
- Security commitments communicated externally
- Risk register maintained and tracked
- Control deficiencies tracked to remediation
- Unauthorized software prevented in production
- Multi-factor authentication enforced
- Quarterly host-based vulnerability scans
- Business continuity exercise performed
- Prohibited AI practices are not used
- Staff using AI have sufficient AI literacy
- Every AI agent in operation is registered
- Every AI agent has a named accountable owner
- AI-generated content is machine-readably marked
- Board oversight of the security program
- Agent autonomy is bounded and approved
- Agent runs are recorded as signed evidence
- People are informed of emotion recognition or biometric categorisation
- Agents can be stopped, and the stop button has been tested
- AI systems in use are inventoried, including unsanctioned ones
- AI tools and models can be denied or disengaged
- Penetration testing performed
- Tool servers agents connect to are approved and unchanged