Skip to main content
Vendo
Security and privacy

Security & Trust

SOC 2 Preparation Summary

An internal audit is in progress. We are documenting Vendo's security controls and evidence for an internal review of the Security category of the SOC 2 Trust Services Criteria. That is not a confirmed independent examination scope.

We are checking control ownership, implementation, and operating evidence. These levels are our own working assessment; none of these areas has been independently verified for Vendo. We have not published an independent SOC 2 report on this site. This page is not an audit opinion, attestation, or certification.

Readiness summary updated 23 September 2026

Our working assessment

Readiness by control area

The level describes the maturity of evidence for each area, not the number of checks passed. Level 0 means no dependable internal evidence; Level 1 means a process is documented or a material gap remains; Level 2 means an implementation is present but operating evidence is incomplete; Level 3 requires current operating evidence reviewed by a Vendo control owner. The bullets identify evidence found and open checks; the identity and access checklist below lists every AICPA Point of Focus for CC6.1–CC6.3. These levels are internal working assessments, not auditor grades or fractions of checks passed.

Swipe the table sideways to read every column.

Vendo internal SOC 2 readiness levels and external verification by control area, updated 23 September 2026
Readiness itemReadiness levelPassing checksOpen checksExternally verified
Identity and accessTrust Services Criteria: CC6.1, CC6.2, CC6.3
Level 2Implemented; evidence incomplete
  • Application workspace roles and account checks (design evidence)
  • Privileged admin AAL2 path found; one Vercel offboarding action checked internally
  • Reconcile human and service identities, inherited roles, and direct data grants
  • Complete offboarding evidence and approve a recurring access-review process
No
Customer data separation
Level 2Implemented; evidence incomplete
  • Account-scoped database policies
  • Warehouse dataset boundaries
  • Review service access
  • Evidence live cross-account isolation
No
Encryption and credentials
Level 1Documented or material gap
  • Encrypted transport
  • Connected-platform credential encryption
  • Complete active credential remediation
  • Evidence rotation and review
No
Change management
Level 2Implemented; evidence incomplete
  • Source-controlled changes
  • Automated checks on sampled changes
  • Record change approvals
  • Verify deployments and resolve recorded exceptions
No
Audit records and monitoring
Level 1Documented or material gap
  • Application audit records
  • Staging admin attribution check
  • Verify admin audit records in production
  • Evidence regular security log review
No
Incident response
Level 1Documented or material gap
  • Response runbook
  • Escalation steps
  • Review the updated runbook
  • Complete a tabletop exercise
No
Backup and recovery
Level 1Documented or material gap
  • Documented backup process
  • Recent backup archives
  • Close backup coverage gaps
  • Complete an isolated restoration drill
No
Vendors and subprocessors
Level 1Documented or material gap
  • Internal vendor inventory
  • Review checklist
  • Review contracts and customer notices
  • Complete overdue vendor review
No
Security governance and risk
Level 1Documented or material gap
  • Security policies
  • Control map
  • Confirm control owners
  • Evidence periodic risk and personnel reviews
No

Identity and access

Numbered criteria checklist

This checklist covers all AICPA Points of Focus under CC6.1, CC6.2, and CC6.3. The AICPA describes Points of Focus as guidance for evaluating the criteria and does not require every point to be addressed. We include each here to show our internal evidence status and the gap that remains. None has independent external verification.

Partial means some design or implementation evidence was found but evidence is incomplete. Open means a known action or evidence is still outstanding. Not assessed means this review did not establish evidence for the item.

Reference: AICPA 2017 Trust Services Criteria, revised Points of Focus (2022). Vendo's checklist paraphrases the applicable Points of Focus.

CC6.1

Logical access protection

Logical access safeguards protect Vendo information assets from security events.

Overall: PartialExternal verification: No
  1. Keep an inventory of information assets
    Open

    Evidence found: Some applications and infrastructure were reviewed.

    Gap: Create and maintain a complete, owner-reviewed inventory with classifications.

  2. Limit logical access to information assets
    Partial

    Evidence found: Workspace roles and account-scoped application checks are present.

    Gap: Reconcile current provider identities and inherited data grants.

  3. Identify and authenticate users and systems
    Partial

    Evidence found: The V2 privileged admin path uses individual identities and AAL2.

    Gap: Complete current identity and MFA evidence across workforce and service accounts.

  4. Separate unrelated parts of the network where appropriate
    Not assessed

    Evidence found: No current network-segmentation evidence was reviewed for this checklist.

    Gap: Map relevant production and staging boundaries and retain a reviewed test or configuration record.

  5. Inventory and manage external connection points
    Open

    Evidence found: Product materials describe integrations, but no complete access-point review was evidenced.

    Gap: Complete an owner-reviewed inventory of administrative access points and the data that flows through them.

  6. Define access rules for each protected asset
    Partial

    Evidence found: Account-scoped policies and warehouse boundaries are documented.

    Gap: Prove current direct-resource permissions and cross-account denial behavior.

  7. Document identity and authentication requirements
    Partial

    Evidence found: AAL2 is used on the reviewed privileged admin path.

    Gap: Approve and evidence consistent identity, MFA, and authentication requirements for every in-scope identity.

  8. Manage infrastructure and software credentials through their lifecycle
    Partial

    Evidence found: Secret-store based runtime credentials and rotation controls are present in reviewed deployments.

    Gap: Complete credential inventory, access review, retirement, and operating evidence.

  9. Use encryption for stored data when risk calls for it
    Not assessed

    Evidence found: At-rest encryption settings were not assessed in this access review.

    Gap: Record the risk decision and verify relevant storage encryption settings.

  10. Protect encryption keys from creation through destruction
    Partial

    Evidence found: Key rotation and managed runtime-secret controls are present.

    Gap: Retain owner-reviewed lifecycle, access, and incident-follow-up evidence.

CC6.2

User registration and removal

Authorize users before issuing access credentials and remove credentials when access is no longer approved.

Overall: OpenExternal verification: No
  1. Issue credentials only after asset-owner approval
    Partial

    Evidence found: Named user identities are in use on reviewed administrative services.

    Gap: Approve a documented request, owner-approval, and recordkeeping process for new access.

  2. Remove credentials when access is no longer authorized
    Partial

    Evidence found: One Vercel offboarding action was checked internally.

    Gap: Complete the requested repository offboarding and verify removal across all relevant providers.

  3. Periodically review who holds access credentials
    Open

    Evidence found: The access-management procedure is drafted.

    Gap: Approve and perform a dated review of all provider rosters, roles, and direct grants.

CC6.3

Role-based access changes

Grant, change, and remove protected-asset access by role and responsibility, applying least privilege and separation of duties.

Overall: OpenExternal verification: No
  1. Approve and record access creation or changes
    Partial

    Evidence found: Application workspace roles and authorization checks are present.

    Gap: Approve and retain owner-authorized records for changes to protected-asset access.

  2. Remove protected-asset access when it is no longer needed
    Open

    Evidence found: A Vercel removal was checked internally.

    Gap: Complete and evidence offboarding across code, cloud, data, and service providers.

  3. Use roles to limit access and separate incompatible duties
    Partial

    Evidence found: Role-based access exists in the application.

    Gap: Reconcile provider permissions against approved duties and least-privilege targets.

  4. Review roles and access rules periodically
    Open

    Evidence found: A review process is proposed in the draft access procedure.

    Gap: Approve the review cadence, complete the first review, and retain dated evidence of changes.

Open checks include missing evidence and known gaps. This snapshot reflects a review of documentation, source code, a staging admin audit check, and limited production backup inspection. It is not a comprehensive production control test. Levels will change as dated operating evidence is reviewed.