All topics Type I — Q3 FY26
Overview
SOC 2 is the de-facto enterprise audit. Our control environment is mapped against the five Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy). We're in active engagement with our auditor for Type I certification this fiscal; Type II follows after a 6-month observation window.
Roadmap
Type I report
Targeted Q3 FY26 (Sep 2026). Audit firm: A.P. Sanzgiri & Co., Mumbai.
Type II report
Targeted Q1 FY27 (Apr 2027) after the 6-month observation window required by AICPA.
ISO 27001
Stage 1 audit complete (Mar 2026). Stage 2 + certification scheduled for Q4 FY26.
Controls already in production
Access management
SSO via OIDC, MFA enforced on every admin role, role-based access via the RBAC matrix in /settings/users.
Change management
All production changes via GitHub PR + 2-reviewer approval. CI runs lint + tests + DAST scan before merge.
Logging & monitoring
Structured logs to Azure Monitor with 90-day hot retention + 1-year cold. Metrics and alerts on every microservice.
Vendor risk
Sub-processor list maintained in /trust/sub-processors with annual review. SOC 2 reports requested from every vendor handling customer data.
Vulnerability management
Weekly scan of dependencies (Renovate + Snyk). External pentest annually; remediation SLA: critical 7 days, high 30 days.
Artifacts & references
Public docs link directly. Confidential artifacts available under NDA — request via enterprise sales.
- Sub-processor list
- Bridge letter (interim) Available under NDA — request via enterprise sales.
