Compliance claims are normalized from current vendor documentation and independently reviewed by SOTA2.
ISO/IEC 27001
245 security controls across asset management, business continuity, cryptography, identity and access management, incident response, network operations, privacy, proactive security, risk management, systems monitoring, third-party management, and vulnerability management
13 policies and resources including code of conduct, ISMS scope and context, incident response plan, access control policy, secure development and change management policy, and third-party risk and supplier security policy
Continuously monitored compliance
Independently audited
Data retention:
Benchmarks and comparisons
Independent benchmarksStructured task results are being verified.
Side-by-side comparisonsComparison workspaces will be available in a later release.