Acme Corp (Demo) Trust Center
Contact [email protected]
All Systems Operational · Infrastructure monitored 24/7 View real-time status ↗
Security Posture  ·  Updated 2026-08-24

Acme Corp — Security & Compliance Overview

Security and compliance documentation for vendor risk assessment.

SOC 2 Type II Certification
ISO 27001:2022 Certification
11 Frameworks Mapped & Continuously Tracked
24 / 7 Active Security Monitoring

Our Active Compliance Programs

Real-time view of where we stand across our committed frameworks. Numbers update from the same control evidence we use internally.

ISO 27001
v2022
Library Loaded
39 controls catalogued Attestation in progress
ISMS scope and statement of applicability under review.
SOC 2
v2022
Library Loaded
39 controls catalogued Attestation in progress
Type 1 attestation targeted Q3 2026.
NIST CSF
v2.0
Library Loaded
31 controls catalogued Attestation in progress
Identify-Protect-Detect-Respond-Recover across the program.
NIST 800-171
vRev 2
Library Loaded
110 controls catalogued Attestation in progress
Controls and evidence reviewed quarterly.
CIS v8.1
v8.1
Library Loaded
21 controls catalogued Attestation in progress
Foundational controls baseline across all managed endpoints.
HIPAA
v2024
Library Loaded
19 controls catalogued Attestation in progress
Healthcare client safeguards — administrative, physical, technical.
PCI DSS
v4.0
Library Loaded
20 controls catalogued Attestation in progress
Cardholder data is out-of-scope by design (link-out billing).
CMMC L1
v2.0
Library Loaded
13 controls catalogued Attestation in progress
Controls and evidence reviewed quarterly.
CMMC L2
v2.0
Library Loaded
57 controls catalogued Attestation in progress
Controls and evidence reviewed quarterly.
CJIS 6.0
v6.0
Library Loaded
13 controls catalogued Attestation in progress
Controls and evidence reviewed quarterly.
NY DFS 500
v2023
Library Loaded
16 controls catalogued Attestation in progress
Controls and evidence reviewed quarterly.

How Your Data Is Secured

The control families operated by Intelligent Automation — the platform that hosts and secures this Trust Center.

Identity & Access

Zitadel SSO with Argos Verify push MFA on every staff login. Least-privilege roles, scoped service accounts, no shared credentials.

Endpoint Defense

Sophos MDR XDR on every managed endpoint. Argos Patch drives continuous remediation with security-only rings and audit-first dispatch.

Network

Cloudflare-fronted public ingress. Admin access is Tailscale-only — no public SSH, no exposed control planes.

Data Protection

Encrypted at rest (DigitalOcean volumes + DO Spaces SSE) and in transit (TLS 1.2+). Secrets segregated per-tenant.

Continuous Monitoring

CrowdSec behavioural IDS, cAdvisor and Uptime-Kuma. Per-container telemetry retained at 1-minute resolution for incident forensics.

Incident Response

DFIR-IRIS-style runbooks with blast-radius mapping across the dependency graph. 24-hour SLA on critical incidents.

Sub-processors

Third-party services that may process data on behalf of Intelligent Automation, the platform operator. Each is reviewed annually.

Provider Service Data Region Last Reviewed Trust Page
Amazon Web Services Cloud hosting & storage us-east-1 2026-06 aws.amazon.com/compliance ↗
Stripe Payment processing USA 2026-06 stripe.com/privacy ↗
Google Workspace Email & productivity USA 2026-06 workspace.google.com/terms/dpa_terms.html ↗

Documents & Reports

Security and compliance documentation. Public items download directly; gated items require a quick access request.

Need our SOC 2 readiness package or full controls evidence?

Sign a mutual NDA in 2 minutes and we'll deliver the complete report — controls matrix, sub-processor list, recent assessment outputs, and remediation status.

Request the Full Trust Report