Security & Trust
SOC 2 Preparation Summary
An internal audit is in progress. We are documenting Vendo's security controls and evidence for an internal review of the Security category of the SOC 2 Trust Services Criteria. That is not a confirmed independent examination scope.
We are checking control ownership, implementation, and operating evidence. These levels are our own working assessment; none of these areas has been independently verified for Vendo. We have not published an independent SOC 2 report on this site. This page is not an audit opinion, attestation, or certification.
Readiness summary updated 23 September 2026
Our working assessment
Readiness by control area
The level describes the maturity of evidence for each area, not the number of checks passed. Level 0 means no dependable internal evidence; Level 1 means a process is documented or a material gap remains; Level 2 means an implementation is present but operating evidence is incomplete; Level 3 requires current operating evidence reviewed by a Vendo control owner. The bullets identify evidence found and open checks; the identity and access checklist below lists every AICPA Point of Focus for CC6.1–CC6.3. These levels are internal working assessments, not auditor grades or fractions of checks passed.
Swipe the table sideways to read every column.
| Readiness item | Readiness level | Passing checks | Open checks | Externally verified |
|---|---|---|---|---|
| Identity and accessTrust Services Criteria: CC6.1, CC6.2, CC6.3 | Level 2Implemented; evidence incomplete |
|
| No |
| Customer data separation | Level 2Implemented; evidence incomplete |
|
| No |
| Encryption and credentials | Level 1Documented or material gap |
|
| No |
| Change management | Level 2Implemented; evidence incomplete |
|
| No |
| Audit records and monitoring | Level 1Documented or material gap |
|
| No |
| Incident response | Level 1Documented or material gap |
|
| No |
| Backup and recovery | Level 1Documented or material gap |
|
| No |
| Vendors and subprocessors | Level 1Documented or material gap |
|
| No |
| Security governance and risk | Level 1Documented or material gap |
|
| No |
Identity and access
Numbered criteria checklist
This checklist covers all AICPA Points of Focus under CC6.1, CC6.2, and CC6.3. The AICPA describes Points of Focus as guidance for evaluating the criteria and does not require every point to be addressed. We include each here to show our internal evidence status and the gap that remains. None has independent external verification.
Partial means some design or implementation evidence was found but evidence is incomplete. Open means a known action or evidence is still outstanding. Not assessed means this review did not establish evidence for the item.
Reference: AICPA 2017 Trust Services Criteria, revised Points of Focus (2022). Vendo's checklist paraphrases the applicable Points of Focus.
CC6.1
Logical access protection
Logical access safeguards protect Vendo information assets from security events.
Keep an inventory of information assets
OpenEvidence found: Some applications and infrastructure were reviewed.
Gap: Create and maintain a complete, owner-reviewed inventory with classifications.
Limit logical access to information assets
PartialEvidence found: Workspace roles and account-scoped application checks are present.
Gap: Reconcile current provider identities and inherited data grants.
Identify and authenticate users and systems
PartialEvidence found: The V2 privileged admin path uses individual identities and AAL2.
Gap: Complete current identity and MFA evidence across workforce and service accounts.
Separate unrelated parts of the network where appropriate
Not assessedEvidence found: No current network-segmentation evidence was reviewed for this checklist.
Gap: Map relevant production and staging boundaries and retain a reviewed test or configuration record.
Inventory and manage external connection points
OpenEvidence found: Product materials describe integrations, but no complete access-point review was evidenced.
Gap: Complete an owner-reviewed inventory of administrative access points and the data that flows through them.
Define access rules for each protected asset
PartialEvidence found: Account-scoped policies and warehouse boundaries are documented.
Gap: Prove current direct-resource permissions and cross-account denial behavior.
Document identity and authentication requirements
PartialEvidence found: AAL2 is used on the reviewed privileged admin path.
Gap: Approve and evidence consistent identity, MFA, and authentication requirements for every in-scope identity.
Manage infrastructure and software credentials through their lifecycle
PartialEvidence found: Secret-store based runtime credentials and rotation controls are present in reviewed deployments.
Gap: Complete credential inventory, access review, retirement, and operating evidence.
Use encryption for stored data when risk calls for it
Not assessedEvidence found: At-rest encryption settings were not assessed in this access review.
Gap: Record the risk decision and verify relevant storage encryption settings.
Protect encryption keys from creation through destruction
PartialEvidence found: Key rotation and managed runtime-secret controls are present.
Gap: Retain owner-reviewed lifecycle, access, and incident-follow-up evidence.
CC6.2
User registration and removal
Authorize users before issuing access credentials and remove credentials when access is no longer approved.
Issue credentials only after asset-owner approval
PartialEvidence found: Named user identities are in use on reviewed administrative services.
Gap: Approve a documented request, owner-approval, and recordkeeping process for new access.
Remove credentials when access is no longer authorized
PartialEvidence found: One Vercel offboarding action was checked internally.
Gap: Complete the requested repository offboarding and verify removal across all relevant providers.
Periodically review who holds access credentials
OpenEvidence found: The access-management procedure is drafted.
Gap: Approve and perform a dated review of all provider rosters, roles, and direct grants.
CC6.3
Role-based access changes
Grant, change, and remove protected-asset access by role and responsibility, applying least privilege and separation of duties.
Approve and record access creation or changes
PartialEvidence found: Application workspace roles and authorization checks are present.
Gap: Approve and retain owner-authorized records for changes to protected-asset access.
Remove protected-asset access when it is no longer needed
OpenEvidence found: A Vercel removal was checked internally.
Gap: Complete and evidence offboarding across code, cloud, data, and service providers.
Use roles to limit access and separate incompatible duties
PartialEvidence found: Role-based access exists in the application.
Gap: Reconcile provider permissions against approved duties and least-privilege targets.
Review roles and access rules periodically
OpenEvidence found: A review process is proposed in the draft access procedure.
Gap: Approve the review cadence, complete the first review, and retain dated evidence of changes.
Open checks include missing evidence and known gaps. This snapshot reflects a review of documentation, source code, a staging admin audit check, and limited production backup inspection. It is not a comprehensive production control test. Levels will change as dated operating evidence is reviewed.