Product Security
Vulnerability Management
Vulnerabilities are identified continuously rather than only at audit time. Dependencies, container images and infrastructure are scanned on an ongoing basis, and findings are triaged and remediated against severity-based timelines. Critical issues are addressed immediately, with progressively longer windows for lower severities. The most recent third-party penetration test and its retest closed with no critical, high or medium findings outstanding.
How it is checked
Continuous scanning with severity-based remediation timelines, plus an annual third-party penetration test and retest.
Framework requirements this speaks to
- ISO 27001 A.8.8 (management of technical vulnerabilities)
- SOC 2 Common Criteria - Risk Assessment
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
Need the evidence behind this?
Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.