Live Trust Center

demo's compliance, in the open.

Real-time posture, continuously monitored with signed, RFC-3161 timestamped, tamper-evident evidence - every control independently verifiable.

89of 97 controls passing

Continuously monitored across 7 frameworks. Evidence is signed, timestamped, and hash-chained.

Signed
KMS key
Timestamped
RFC-3161
Chained
append-only

Get in touch

Need the SOC 2 report, a pen-test summary, or to talk to the team? Request access and they will follow up.

Frameworks

SOC 2 (Trust Services Criteria)
33 criteria
HIPAA Security Rule
Not in scope
ISO/IEC 27001:2022 (Annex A)
Not in scope
PCI DSS v4.0
Not in scope
ISO/IEC 42001:2023 (AI management)
Not in scope
NIST AI RMF 1.0
Not in scope
EU AI Act (Regulation 2024/1689)
Not in scope

Monitored controls (97)

Passing Failing Pending
  • Least-privilege IAM
  • S3 account public access blocked
  • Encryption at rest (KMS)
  • TLS for data in transit
  • CloudTrail audit logging
  • AWS Config continuous recording
  • Security Hub finding aggregation
  • GuardDuty threat detection
  • Inspector vulnerability scanning
  • IAM access keys rotated
  • Unused credentials disabled
  • IAM Access Analyzer enabled
  • CloudTrail log-file validation
  • CloudTrail encrypted with KMS
  • VPC flow logs enabled
  • S3 default encryption
  • RDS encrypted at rest
  • RDS not publicly accessible
  • Security Hub findings triaged
  • KMS key rotation enabled
  • AWS Backup plan configured
  • GitHub branch protection
  • GitHub organization requires 2FA
  • No open critical/high Dependabot alerts
  • Security tickets are assigned
  • Ticketed change management
  • Onboarding and offboarding
  • Quarterly access reviews
  • Incident response plan
  • Policy documents match their approved version
  • Board oversight of the security program
  • Code of conduct acknowledged by personnel
  • Organizational structure and reporting lines defined
  • Security roles and responsibilities documented
  • Job descriptions define required competencies
  • Performance reviews hold personnel accountable
  • Confidentiality agreements signed
  • Disciplinary process for policy violations
  • Security policies published to personnel
  • External vulnerability disclosure channel
  • Annual enterprise risk assessment
  • Security awareness training
  • Fraud risk considered in assessment
  • Significant changes assessed for risk
  • Ongoing monitoring of control effectiveness
  • Independent internal control review
  • Subservice organization SOC reports reviewed
  • Control activities mapped to risks
  • Policies reviewed and approved annually
  • Physical access to facilities restricted
  • Secure disposal of data and media
  • Endpoint anti-malware protection
  • Security incidents contained and responded to
  • Incident recovery and post-incident review
  • Breach notification process
  • Business continuity plan maintained
  • Backups performed and restoration tested
  • Cyber insurance coverage maintained
  • Vendors risk-assessed before engagement
  • Vendor and subprocessor inventory maintained
  • Vendor contracts include security terms
  • Internal channel for reporting security concerns
  • Okta MFA enrollment required
  • No stale Okta accounts
  • Okta System Log accessible
  • OpenAI organization owners limited
  • Anthropic organization admins limited
  • Anthropic API keys scoped to workspaces
  • Microsoft 365 Global Administrators limited
  • Microsoft 365 Conditional Access requires MFA
  • AI usage logged to the signed evidence ledger
  • Segregation of duties enforced
  • AI gateway enforces data-loss protection
  • Prompt injection monitored at the AI gateway
  • Disaster recovery exercise performed
  • Audit logging enabled
  • Vulnerability scanning in place
  • Least-privilege access
  • Change management and code review
  • Network access segmented
  • Background checks performed
  • MFA enforced on all human access
  • Strong IAM password policy
  • Root account hardened
  • EBS default encryption
  • No SSH/RDP open to the world
  • Default security group restricts all traffic
  • Managed device security
  • Security commitments communicated externally
  • Risk register maintained and tracked
  • Control deficiencies tracked to remediation
  • Unauthorized software prevented in production
  • Multi-factor authentication enforced
  • Data center physical security inherited from cloud provider
  • Microsoft 365 Conditional Access requires phishing-resistant MFA
  • Quarterly host-based vulnerability scans
  • Business continuity exercise performed

Follow this Trust Center

Get an email when a new document or update is published.