Product Security

Change Management

Changes to infrastructure and software are documented, reviewed and approved before they reach production, under a change management policy that is reviewed and approved annually. Development and production are separate environments, and engineers do not hold standing access to production or to production databases. Access for a specific project is granted deliberately, logged and reviewed.

How it is checked

Approvals recorded in the change management system and sampled in our SOC 2 Type II examination.

Framework requirements this speaks to

  • ISO 27001 A.8.32 (change management)
  • ISO 27001 A.8.31 (separation of development, test and production environments)
  • SOC 2 Common Criteria - Change Management

Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.

Need the evidence behind this?

Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.