Skip to content
Security program · not a certificate

SOC 2 readiness, tracked against an open methodology

We prepare using the published Chiaro control library (CC BY 4.0) — the same bar for readiness that the method uses for examination. This page shows our program status. It is not a SOC 2 report and does not mean we are certified.

Honest claim language

This is an internal readiness tracker. It is NOT a SOC 2 report and does not claim certification. Only a licensed CPA firm may issue a SOC 2 opinion. Only a licensed CPA firm may sign a SOC 2 opinion under AT-C 205. Anyone may run readiness against the open methodology with attribution.

Readiness score

54.7%

Weighted across 81 applicable controls

Controls

89

From Chiaro library · 8 marked N/A

Status mix

Evidenced: 0Implemented: 43In progress: 14Planned: 24Not started: 0N/A: 8

Why we use an open methodology

Same bar for prep and exam

Chiaro publishes the control library and criteria so readiness is not a black box.

You can check our work

Status is control-by-control. Ask us for evidence on any ID before or during a pilot.

No vibe compliance

We will not claim SOC 2 certified until an independent report exists — period.

Control matrix

Titles and categories from the Chiaro methodology (CC BY 4.0). Status and notes are PhishGuard’s internal program tracking.

AI & MODEL GOVERNANCE

0% · 4 controls

IDControlStatusTSCNotes
AI-01AI Provider Inventory & Data-Use TermsN/ACC9.2, C1.1No customer-facing generative AI control surface in core product yet
AI-02Model Provider Data-Use ConfigurationN/AC1.1, CC9.2No model training on customer mailbox content
AI-03Customer Data Boundaries for AI FeaturesN/AC1.1, CC6.7AI features not productized
AI-04AI Interaction Logging & RetentionN/ACC6.7, C1.1, C1.2AI features not productized

ASSET & DATA MANAGEMENT

58.3% · 3 controls

IDControlStatusTSCNotes
AST-01Information Asset InventoryImplementedCC2.1, CC6.1Systems inventory via access inventory
AST-02Data ClassificationImplementedCC2.1, CC6.7, C1.1Data inventory via RoPA + classification policy
AST-03SaaS & Data Asset InventoryPlannedCC2.1, CC6.1Media disposal

AVAILABILITY

47.5% · 2 controls

IDControlStatusTSCNotes
AVL-01Capacity Monitoring & PlanningImplementedA1.1GET /api/health for uptime monitors
AVL-02Availability Monitoring & Uptime ResponsePlannedA1.1, CC7.2Capacity planning for large directory syncs

BUSINESS CONTINUITY & DISASTER RECOVERY

80% · 3 controls

IDControlStatusTSCNotes
BCP-01BCP/DR Plan & TestingImplementedCC9.1, A1.3, CC8.1Backup procedure + RPO/RTO targets documented
BCP-02Data Backup & Recovery InfrastructureImplementedCC9.1, A1.2, A1.3, C1.1RTO/RPO targets in BC pilot + backup docs
BCP-03Backup & Recovery Provider-ManagedImplementedCC9.1, A1.2, A1.3, C1.1Pilot support windows + founder on-call in BC plan

CHANGE MANAGEMENT

69.2% · 6 controls

IDControlStatusTSCNotes
CHG-01Change Management ProcessImplementedCC8.1Git-based change + secure development policy
CHG-02Emergency Change ProcessImplementedCC8.1CI: compliance, typecheck, lint, build, readiness reports
CHG-03Environment SeparationImplementedCC8.1Live-send enable procedure in operating procedures
CHG-04Secure Development LifecycleImplementedCC8.1Automated compliance scanner for claims/harvest/dry-run
CHG-05Security Architecture ReviewImplementedCC6.1Emergency change procedure
CHG-06Change Control Automated GatesPlannedCC8.1Infrastructure-as-code change control

CONTROL MONITORING

80% · 2 controls

IDControlStatusTSCNotes
EVL-01Ongoing Control Monitoring & EvaluationImplementedCC4.1Compliance automation + go/no-go + readiness trackers
EVL-02Deficiency Tracking & RemediationImplementedCC4.2Self-assessment cadence documented

DATA PROTECTION

60% · 5 controls

IDControlStatusTSCNotes
DAT-01Encryption at Rest & in TransitIn progressCC6.1, CC6.7TLS in transit via platform; at-rest via host/DB provider
DAT-02Secure Data & Asset DisposalImplementedCC6.5, C1.2, P4.3Canada-oriented residency posture on security/privacy pages
DAT-03Data Retention & DeletionPlannedCC6.5, CC6.7, C1.1, P4.2, P4.3Key management for per-org Google credentials
DAT-04Production Data in Non-Production EnvironmentsImplementedCC6.7, CC6.1No credential capture enforced in templates + compliance CI
DAT-05Data Retention & Deletion ExecutionImplementedC1.2Data classification policy v0.1

ENDPOINT SECURITY

45% · 3 controls

IDControlStatusTSCNotes
END-01Endpoint ProtectionIn progressCC6.8Device security checklist for founder/admin devices
END-02Software Installation ControlsIn progressCC6.8Malware protection required on device checklist
END-03Endpoint Protection Founder-Managed DevicesIn progressCC6.8Device checklist covers admin endpoints

EXTERNAL COMMUNICATION

80% · 2 controls

IDControlStatusTSCNotes
COM-01Customer Commitments & Service DescriptionsImplementedCC2.3Security package hub + public trust pages
COM-02External Reporting & Inbound CommunicationImplementedCC2.3security@ / privacy@ + customer FAQ pack

GOVERNANCE & ETHICS

31.3% · 4 controls

IDControlStatusTSCNotes
GOV-01Code of Conduct & EthicsPlannedCC1.1, CC1.5Draft code of conduct before first pilot hire/contractor scale
GOV-02Governance OversightPlannedCC1.2Board/advisor security oversight not yet formalized
GOV-03Organizational Structure & ResponsibilitiesImplementedCC1.3Security roles founder + documented
GOV-04Leadership & Advisor Oversight of SecurityPlannedCC1.2Background checks policy for future hires

IDENTITY & ACCESS MANAGEMENT

53% · 11 controls

IDControlStatusTSCNotes
HIP-02Emergency Access ProcedureN/ACC6.1, CC6.3HIPAA not in product scope for current Canadian wedge
IAM-01User AuthenticationIn progressCC6.1Better Auth + sessions; production MFA enforcement pending
IAM-02Multi-Factor AuthenticationImplementedCC6.1, CC6.6MFA policy required for all prod systems; inventory tracks status
IAM-03User Access ProvisioningImplementedCC6.2App role model documented + in product types
IAM-04User Access DeprovisioningIn progressCC6.2Quarterly access review cadence started
IAM-05Periodic User Access ReviewsIn progressCC6.2, CC6.3Access review log + joiner/leaver in access policy
IAM-06Role-Based Access & Least PrivilegeImplementedCC6.3Privileged access inventory + quarterly review
IAM-07Privileged Access ManagementIn progressCC6.3, CC6.1Service accounts for Google DWD per-org design
IAM-08Service Account & Infrastructure CredentialsPlannedCC6.1Session timeout policy documented
IAM-09Access Review Founder AttestationImplementedCC6.2, CC6.3MFA/auth policy covers password manager + unique creds
IAM-11Third-Party App & OAuth Integration ReviewPlannedCC6.1, CC6.6API key lifecycle for future customer API

INCIDENT RESPONSE

80% · 4 controls

IDControlStatusTSCNotes
INC-01Incident Response Plan & TrainingImplementedCC7.4IR plan v0.1
INC-02Incident Response ExecutionImplementedCC7.4, CC7.5Severity + response in IR plan
INC-03Incident Response Solo OperatorImplementedCC7.4Customer/authority notify targets in IR plan
INC-04Post-Incident Review & Corrective ActionsImplementedCC7.5Post-incident review in IR plan

NETWORK & INFRASTRUCTURE

22.5% · 4 controls

IDControlStatusTSCNotes
NET-01Network IsolationIn progressCC6.1Platform network controls via Vercel/host
NET-02Boundary ProtectionPlannedCC6.6WAF/rate limits on public endpoints
NET-03Physical Access ControlsPlannedCC6.4Segregation of prod/staging
NET-04Production Platform Hardening Managed PlatformsPlannedCC6.1Remote access policy

PEOPLE

46% · 6 controls

IDControlStatusTSCNotes
PPL-01Background ChecksIn progressCC1.4Onboarding via access policy + device checklist
PPL-02Job Descriptions & CompetencyIn progressCC1.4AUP + security policy awareness for anyone with access
PPL-03Training & Competency DevelopmentPlannedCC1.4, CC2.2Offboarding checklist
PPL-04Performance & AccountabilityN/ACC1.5No employees yet; disciplinary process when first hire
PPL-05Key Personnel & ContinuityImplementedCC1.4Acceptable use policy v0.1
PPL-06Contractor & Outsourced Personnel ControlsIn progressCC1.5Security requirements for contractors via AUP + agreements

POLICY & DOCUMENTATION

80% · 3 controls

IDControlStatusTSCNotes
HIP-03Security Documentation RetentionN/ACC5.3HIPAA not in scope for current Canadian municipal GWS product wedge
POL-01Policy Suite & GovernanceImplementedCC5.3, CC3.1Information security policy v0.1 approved
POL-02Policy Communication & AccessibilityImplementedCC2.2Public privacy policy live at /privacy

PRIVACY

60.5% · 10 controls

IDControlStatusTSCNotes
PRI-01Privacy Notice & CommunicationImplementedP1.1Purpose limitation in privacy policy + product design
PRI-02Consent ManagementImplementedP2.1DSAR playbook + internal lead inbox for controller data
PRI-03Personal Information CollectionImplementedP3.1, P3.2Canadian privacy framing in policy + program docs
PRI-04Use & Purpose LimitationImplementedP4.1Retention schedule v0.1
PRI-05Data Subject Access & Correction RightsImplementedP5.1, P5.2Deletion runbook v0.1
PRI-06Disclosure & Third-Party ManagementImplementedP6.1, P6.2, P6.3, P6.4, P6.5Lead form privacy consent + policy link
PRI-07Privacy Breach NotificationImplementedP6.6No employee password collection
PRI-08Data Subject Accounting RequestsPlannedP6.7Cross-border transfer assessment if any US subprocessors
PRI-09Data QualityPlannedP7.1Privacy training for staff
PRI-10Privacy Monitoring & Dispute ResolutionPlannedP8.1Privacy impact assessment template for customers

PROCESSING INTEGRITY

41% · 5 controls

IDControlStatusTSCNotes
INT-01Processing Specifications & RequirementsImplementedPI1.1Dry-run default + seat/campaign controls in product
INT-02Input ValidationPlannedPI1.2Data validation on imports/sync
INT-03Processing Accuracy & CompletenessImplementedPI1.3Tenant isolation design + cross-tenant test plan
INT-04Output ControlsPlannedPI1.4Job completeness for sync/send
INT-05Data Storage IntegrityPlannedPI1.5Error handling SLAs

RISK MANAGEMENT

47.5% · 2 controls

IDControlStatusTSCNotes
RSK-01Annual Risk AssessmentPlannedCC3.1, CC3.2, CC3.3, CC3.4Annual risk assessment process
RSK-02Risk-Based Control DesignImplementedCC5.1, CC5.2Risk tracked via go/no-go, SoA, remediation playbook

SECURITY MONITORING

36.7% · 3 controls

IDControlStatusTSCNotes
MON-01Security LoggingPlannedCC7.2Centralized app logging in production
MON-02Security Alerting & Event TriagePlannedCC7.2, CC7.3Security alerting (failed auth, anomalous admin)
MON-03Security Logging Platform-NativeImplementedCC7.2Admin audit log in product

VENDOR MANAGEMENT

68.3% · 4 controls

IDControlStatusTSCNotes
HIP-01Business Associate AgreementsN/ACC9.2HIPAA BAA path not in current product scope
VND-01Vendor Risk ManagementImplementedCC9.2Vendor risk via policy, ISO control map, and contract control checklist
VND-02Subservice Organization MonitoringIn progressCC9.2Annual vendor review in vendor policy
VND-04Subprocessor Change Management & NotificationImplementedCC9.2Written notification process: 10 business day notice, objection window, changelog, public page, email template

VULNERABILITY MANAGEMENT

25% · 3 controls

IDControlStatusTSCNotes
VUL-01Vulnerability ScanningIn progressCC7.1npm audit in CI (high+)
VUL-02Penetration TestingPlannedCC7.1Vulnerability remediation SLAs
VUL-04Dependency & Platform Update ManagementPlannedCC7.1Penetration test before scale

Evaluating PhishGuard?

We share this tracker, our security overview, and interim evidence pack on request — without pretending a certificate we do not have.

Control library © Chiaro methodology contributors · github.com/Chiaro-HQ/methodology · CC BY 4.0