Live Trust Centerdemo's compliance, in the open.
Real-time posture, continuously monitored with signed, RFC-3161 timestamped, tamper-evident evidence - every control independently verifiable.
89of 97 controls passing
Continuously monitored across 7 frameworks. Evidence is signed, timestamped, and hash-chained.
Get in touch
Need the SOC 2 report, a pen-test summary, or to talk to the team? Request access and they will follow up.
Frameworks
SOC 2 (Trust Services Criteria)
33 criteria
HIPAA Security Rule
Not in scope
ISO/IEC 27001:2022 (Annex A)
Not in scope
ISO/IEC 42001:2023 (AI management)
Not in scope
NIST AI RMF 1.0
Not in scope
EU AI Act (Regulation 2024/1689)
Not in scope
Monitored controls (97)
Passing Failing Pending
- Least-privilege IAM
- S3 account public access blocked
- Encryption at rest (KMS)
- TLS for data in transit
- CloudTrail audit logging
- AWS Config continuous recording
- Security Hub finding aggregation
- GuardDuty threat detection
- Inspector vulnerability scanning
- IAM access keys rotated
- Unused credentials disabled
- IAM Access Analyzer enabled
- CloudTrail log-file validation
- CloudTrail encrypted with KMS
- VPC flow logs enabled
- S3 default encryption
- RDS encrypted at rest
- RDS not publicly accessible
- Security Hub findings triaged
- KMS key rotation enabled
- AWS Backup plan configured
- GitHub branch protection
- GitHub organization requires 2FA
- No open critical/high Dependabot alerts
- Security tickets are assigned
- Ticketed change management
- Onboarding and offboarding
- Quarterly access reviews
- Incident response plan
- Policy documents match their approved version
- Board oversight of the security program
- Code of conduct acknowledged by personnel
- Organizational structure and reporting lines defined
- Security roles and responsibilities documented
- Job descriptions define required competencies
- Performance reviews hold personnel accountable
- Confidentiality agreements signed
- Disciplinary process for policy violations
- Security policies published to personnel
- External vulnerability disclosure channel
- Annual enterprise risk assessment
- Security awareness training
- Fraud risk considered in assessment
- Significant changes assessed for risk
- Ongoing monitoring of control effectiveness
- Independent internal control review
- Subservice organization SOC reports reviewed
- Control activities mapped to risks
- Policies reviewed and approved annually
- Physical access to facilities restricted
- Secure disposal of data and media
- Endpoint anti-malware protection
- Security incidents contained and responded to
- Incident recovery and post-incident review
- Breach notification process
- Business continuity plan maintained
- Backups performed and restoration tested
- Cyber insurance coverage maintained
- Vendors risk-assessed before engagement
- Vendor and subprocessor inventory maintained
- Vendor contracts include security terms
- Internal channel for reporting security concerns
- Okta MFA enrollment required
- No stale Okta accounts
- Okta System Log accessible
- OpenAI organization owners limited
- Anthropic organization admins limited
- Anthropic API keys scoped to workspaces
- Microsoft 365 Global Administrators limited
- Microsoft 365 Conditional Access requires MFA
- AI usage logged to the signed evidence ledger
- Segregation of duties enforced
- AI gateway enforces data-loss protection
- Prompt injection monitored at the AI gateway
- Disaster recovery exercise performed
- Audit logging enabled
- Vulnerability scanning in place
- Least-privilege access
- Change management and code review
- Network access segmented
- Background checks performed
- MFA enforced on all human access
- Strong IAM password policy
- Root account hardened
- EBS default encryption
- No SSH/RDP open to the world
- Default security group restricts all traffic
- Managed device security
- Security commitments communicated externally
- Risk register maintained and tracked
- Control deficiencies tracked to remediation
- Unauthorized software prevented in production
- Multi-factor authentication enforced
- Data center physical security inherited from cloud provider
- Microsoft 365 Conditional Access requires phishing-resistant MFA
- Quarterly host-based vulnerability scans
- Business continuity exercise performed