SOC 2 TYPE II·GDPR·HIPAA
AC

Controls

20 controls across SOC 2, GDPR, and HIPAA

10
Satisfied
5
In Progress
3
At Risk
2
Not Started
REFCONTROLDOMAINSTATUSEVIDENCEUPDATED
CC1.1
Control environment commitment to integrityControl Environment
Satisfied
4
Jun 5, 2026
CC2.1
Information and communication policiesCommunication
Satisfied
3
Jun 3, 2026
CC3.1AI
Risk assessment objectivesRisk Assessment
In Progress
2
Jun 1, 2026
CC6.1
Logical access security — user authenticationLogical Access
Satisfied
6
Jun 7, 2026
CC6.2
Role-based access controlsLogical Access
Satisfied
5
Jun 6, 2026
CC6.3AI
Removal of access upon terminationLogical Access
In Progress
1
May 28, 2026
CC7.1
Vulnerability and infrastructure monitoringSystem Operations
At Risk
0
May 15, 2026
CC7.2AI
Incident detection and response proceduresSystem Operations
In Progress
2
Jun 2, 2026
CC8.1
Change management process and approvalChange Management
Satisfied
7
Jun 4, 2026
A1.1
Availability monitoring and alertingAvailability
At Risk
1
May 20, 2026
GDPR-6
Lawful basis for processing personal dataData Processing
Satisfied
4
Jun 1, 2026
GDPR-13
Transparency — privacy noticeIndividual Rights
Satisfied
3
May 25, 2026
GDPR-17
Right to erasure (right to be forgotten)Individual Rights
Satisfied
2
Jun 3, 2026
GDPR-32
Security of processing — encryption at restData Security
Satisfied
5
Jun 5, 2026
GDPR-33AI
Notification of personal data breachBreach Management
In Progress
1
May 28, 2026
HIPAA-164.308a1
Security management process — risk analysisAdministrative Safeguards
At Risk
0
May 10, 2026
HIPAA-164.308a3AI
Workforce clearance and access managementAdministrative Safeguards
In Progress
1
May 29, 2026
HIPAA-164.312a1
Access controls — unique user identificationTechnical Safeguards
Satisfied
4
Jun 2, 2026
HIPAA-164.312e1
Transmission security — TLS enforcementTechnical Safeguards
Not Started
0
HIPAA-164.316a1
Documentation and policy review processPolicies and Procedures
Not Started
0
Showing 20 of 20 controls