001 mapping.Privacy (P1–P8) — Notice, consent, collection limits, use and retention, access rights, disclosure, security, monitoring and enforcement. Maps closely to ISO 27701 and GDPR principles.5. Minimum Requirements (Non-Negotiable)Mandatory DocumentsSystem Description (the central narrative artifact — see Section 8)Information security policy and supporting policies (access, incident, DR, change management, vendor, encryption, data re
View source ↗Security Consultant SOC 2 status and provider evidence
Review Security Consultant’s public SOC 2 statement, report type, evidence source, and freshness.
Security Consultant’s SOC 2 stack
No provider is named on the current source.
We will update this page if the company publishes more detail.
Frameworks named by Security Consultant
; no periodic HR checks; no evidence of management oversight.Example: Annual leadership review of organizational responsibilities, documented in management review minutes.Mapping: ISO 27001 Clauses 5 and 7.CC2 — Communication & InformationPurpose: Ensure relevant security information is communicated internally and externally.Minimum Expectations: Policies communicated to staff; security incident notification process; customer-facing commitments
View source ↗em Description, remediate control gaps, and represent the program through the engagement. We coordinate with the CPA firm but do not issue the report.What's the difference between SOC 1, SOC 2, and SOC 3?SOC 1 covers controls relevant to financial reporting (ICFR). SOC 2 covers controls relevant to the Trust Services Criteria (security, availability, confidentiality, processing integrity, privacy). SOC 3 is a public-facing general use report
View source ↗deepdiveView all servicesCase StudiesWhy UsResourcesFAQsContact usHomeResourcesSOC 2 DeepdiveFramework DeepdiveSummaryHeading 2Heading 3Heading 4Heading 5Heading 61. OverviewWhat SOC 2 IsSOC 2 (System and Organization Controls 2) is an attestation engagement performed by a licensed CPA firm under the AICPA's attestation standards (SSAE 21, specifically AT-C section 105 and AT-C section 205). The CPA firm reports on whether the service organ
View source ↗mediate control gaps, and represent the program through the engagement. We coordinate with the CPA firm but do not issue the report.What's the difference between SOC 1, SOC 2, and SOC 3?SOC 1 covers controls relevant to financial reporting (ICFR). SOC 2 covers controls relevant to the Trust Services Criteria (security, availability, confidentiality, processing integrity, privacy). SOC 3 is a public-facing general use report based on the same
View source ↗Primary compliance evidence
deepdiveView all servicesCase StudiesWhy UsResourcesFAQsContact usHomeResourcesSOC 2 DeepdiveFramework DeepdiveSummaryHeading 2Heading 3Heading 4Heading 5Heading 61. OverviewWhat SOC 2 IsSOC 2 (System and Organization Controls 2) is an attestation engagement performed by a licensed CPA firm under the AICPA's attestation standards (SSAE 21, specifically AT-C section 105 and AT-C section 205). The CPA firm reports on whether the service organ
Open source ↗