Network and Infrastructure Security
Network Segmentation and Perimeter Protection
Production runs in a segmented AWS VPC with security groups and network ACLs enforcing least-privilege traffic flows. Public endpoints sit behind a web application firewall with DDoS protection at the edge, and firewall rules are configured to permit only approved services. Administrative access to production is not exposed to the public internet and is further restricted by source IP.
How it is checked
Firewall configuration and the restricted administrator list were inspected in our SOC 2 Type II examination, with no deviations noted.
Framework requirements this speaks to
- ISO 27001 A.8.20 (networks security)
- ISO 27001 A.8.22 (segregation of networks)
- ISO 27001 A.8.23 (web filtering)
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
Need the evidence behind this?
Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.