Network and Infrastructure Security
Multi-Factor Authentication
MFA is enforced on all access to production. Access to the production environment, the deployment pipeline and the source control system each require multi-factor authentication and are restricted to authorised personnel. Corporate accounts authenticate through our identity provider with MFA enforced, and privileged accounts are separate from day-to-day accounts.
How it is checked
Tested in our SOC 2 Type II examination against production, deployment and source control access, with no deviations noted.
Framework requirements this speaks to
- ISO 27001 A.5.17 (authentication information)
- ISO 27001 A.8.5 (secure authentication)
- SOC 2 Common Criteria - Logical Access
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
Need the evidence behind this?
Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.