-
Notifications
You must be signed in to change notification settings - Fork 2
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add information about SOC 2 attestation to security page (#77)
- Loading branch information
1 parent
0c11822
commit 5d7c16a
Showing
1 changed file
with
4 additions
and
4 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -6,6 +6,10 @@ export const meta = { | |
|
||
The PrairieLearn team takes the security of our products and services seriously. | ||
|
||
## Third-party audits | ||
|
||
- **SOC 2 Type I**: PrairieLearn, Inc. has a SOC 2 Type I attestation for Security in accordance with the AICPA Trust Service Criteria. [Contact us](/contact) for access to our report. | ||
|
||
## Product security | ||
|
||
- **Software development lifecycle**: PrairieLearn, Inc. follows a secure software development lifecycle, including secure coding practices, code reviews, and automated testing. | ||
|
@@ -18,10 +22,6 @@ The PrairieLearn team takes the security of our products and services seriously. | |
- **Secure remote access**: Internal systems are only accessible via AWS Systems Manager. Access to AWS Systems Manager is logged and tightly controlled. | ||
- **Identity access and management**: PrairieLearn, Inc. uses JumpCloud for identity and access management. Multi-factor authentication is required and utilized wherever possible. | ||
|
||
## Third-party audits | ||
|
||
- **SOC 2 Type I _(coming soon)_**: PrairieLearn, Inc. is currently working with [Vanta](https://www.vanta.com/) and third-party auditors to achieve SOC 2 Type I compliance. We expect to complete this process in early 2024. The completed report will be made available to customers upon request. | ||
|
||
## Reporting a vulnerability | ||
|
||
If you believe you have found a vulnerability in any PrairieLearn software, please report it to us via coordinated disclosure. **Do not report suspected vulnerabilities publicly, including through GitHub issues or public Slack channels.** Instead, please send an email to [[email protected]](mailto:[email protected]) with as much relevant information as possible, including: | ||
|