SOC 2 readiness, tracked against an open methodology
We prepare using the published Chiaro control library (CC BY 4.0) — the same bar for readiness that the method uses for examination. This page shows our program status. It is not a SOC 2 report and does not mean we are certified.
Honest claim language
This is an internal readiness tracker. It is NOT a SOC 2 report and does not claim certification. Only a licensed CPA firm may issue a SOC 2 opinion. Only a licensed CPA firm may sign a SOC 2 opinion under AT-C 205. Anyone may run readiness against the open methodology with attribution.
Readiness score
54.7%
Weighted across 81 applicable controls
Controls
89
From Chiaro library · 8 marked N/A
Status mix
Why we use an open methodology
Same bar for prep and exam
Chiaro publishes the control library and criteria so readiness is not a black box.
You can check our work
Status is control-by-control. Ask us for evidence on any ID before or during a pilot.
No vibe compliance
We will not claim SOC 2 certified until an independent report exists — period.
Control matrix
Titles and categories from the Chiaro methodology (CC BY 4.0). Status and notes are PhishGuard’s internal program tracking.
AI & MODEL GOVERNANCE
0% · 4 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| AI-01 | AI Provider Inventory & Data-Use Terms | N/A | CC9.2, C1.1 | No customer-facing generative AI control surface in core product yet |
| AI-02 | Model Provider Data-Use Configuration | N/A | C1.1, CC9.2 | No model training on customer mailbox content |
| AI-03 | Customer Data Boundaries for AI Features | N/A | C1.1, CC6.7 | AI features not productized |
| AI-04 | AI Interaction Logging & Retention | N/A | CC6.7, C1.1, C1.2 | AI features not productized |
ASSET & DATA MANAGEMENT
58.3% · 3 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| AST-01 | Information Asset Inventory | Implemented | CC2.1, CC6.1 | Systems inventory via access inventory |
| AST-02 | Data Classification | Implemented | CC2.1, CC6.7, C1.1 | Data inventory via RoPA + classification policy |
| AST-03 | SaaS & Data Asset Inventory | Planned | CC2.1, CC6.1 | Media disposal |
AVAILABILITY
47.5% · 2 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| AVL-01 | Capacity Monitoring & Planning | Implemented | A1.1 | GET /api/health for uptime monitors |
| AVL-02 | Availability Monitoring & Uptime Response | Planned | A1.1, CC7.2 | Capacity planning for large directory syncs |
BUSINESS CONTINUITY & DISASTER RECOVERY
80% · 3 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| BCP-01 | BCP/DR Plan & Testing | Implemented | CC9.1, A1.3, CC8.1 | Backup procedure + RPO/RTO targets documented |
| BCP-02 | Data Backup & Recovery Infrastructure | Implemented | CC9.1, A1.2, A1.3, C1.1 | RTO/RPO targets in BC pilot + backup docs |
| BCP-03 | Backup & Recovery Provider-Managed | Implemented | CC9.1, A1.2, A1.3, C1.1 | Pilot support windows + founder on-call in BC plan |
CHANGE MANAGEMENT
69.2% · 6 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| CHG-01 | Change Management Process | Implemented | CC8.1 | Git-based change + secure development policy |
| CHG-02 | Emergency Change Process | Implemented | CC8.1 | CI: compliance, typecheck, lint, build, readiness reports |
| CHG-03 | Environment Separation | Implemented | CC8.1 | Live-send enable procedure in operating procedures |
| CHG-04 | Secure Development Lifecycle | Implemented | CC8.1 | Automated compliance scanner for claims/harvest/dry-run |
| CHG-05 | Security Architecture Review | Implemented | CC6.1 | Emergency change procedure |
| CHG-06 | Change Control Automated Gates | Planned | CC8.1 | Infrastructure-as-code change control |
CONTROL MONITORING
80% · 2 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| EVL-01 | Ongoing Control Monitoring & Evaluation | Implemented | CC4.1 | Compliance automation + go/no-go + readiness trackers |
| EVL-02 | Deficiency Tracking & Remediation | Implemented | CC4.2 | Self-assessment cadence documented |
DATA PROTECTION
60% · 5 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| DAT-01 | Encryption at Rest & in Transit | In progress | CC6.1, CC6.7 | TLS in transit via platform; at-rest via host/DB provider |
| DAT-02 | Secure Data & Asset Disposal | Implemented | CC6.5, C1.2, P4.3 | Canada-oriented residency posture on security/privacy pages |
| DAT-03 | Data Retention & Deletion | Planned | CC6.5, CC6.7, C1.1, P4.2, P4.3 | Key management for per-org Google credentials |
| DAT-04 | Production Data in Non-Production Environments | Implemented | CC6.7, CC6.1 | No credential capture enforced in templates + compliance CI |
| DAT-05 | Data Retention & Deletion Execution | Implemented | C1.2 | Data classification policy v0.1 |
ENDPOINT SECURITY
45% · 3 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| END-01 | Endpoint Protection | In progress | CC6.8 | Device security checklist for founder/admin devices |
| END-02 | Software Installation Controls | In progress | CC6.8 | Malware protection required on device checklist |
| END-03 | Endpoint Protection Founder-Managed Devices | In progress | CC6.8 | Device checklist covers admin endpoints |
EXTERNAL COMMUNICATION
80% · 2 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| COM-01 | Customer Commitments & Service Descriptions | Implemented | CC2.3 | Security package hub + public trust pages |
| COM-02 | External Reporting & Inbound Communication | Implemented | CC2.3 | security@ / privacy@ + customer FAQ pack |
GOVERNANCE & ETHICS
31.3% · 4 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| GOV-01 | Code of Conduct & Ethics | Planned | CC1.1, CC1.5 | Draft code of conduct before first pilot hire/contractor scale |
| GOV-02 | Governance Oversight | Planned | CC1.2 | Board/advisor security oversight not yet formalized |
| GOV-03 | Organizational Structure & Responsibilities | Implemented | CC1.3 | Security roles founder + documented |
| GOV-04 | Leadership & Advisor Oversight of Security | Planned | CC1.2 | Background checks policy for future hires |
IDENTITY & ACCESS MANAGEMENT
53% · 11 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| HIP-02 | Emergency Access Procedure | N/A | CC6.1, CC6.3 | HIPAA not in product scope for current Canadian wedge |
| IAM-01 | User Authentication | In progress | CC6.1 | Better Auth + sessions; production MFA enforcement pending |
| IAM-02 | Multi-Factor Authentication | Implemented | CC6.1, CC6.6 | MFA policy required for all prod systems; inventory tracks status |
| IAM-03 | User Access Provisioning | Implemented | CC6.2 | App role model documented + in product types |
| IAM-04 | User Access Deprovisioning | In progress | CC6.2 | Quarterly access review cadence started |
| IAM-05 | Periodic User Access Reviews | In progress | CC6.2, CC6.3 | Access review log + joiner/leaver in access policy |
| IAM-06 | Role-Based Access & Least Privilege | Implemented | CC6.3 | Privileged access inventory + quarterly review |
| IAM-07 | Privileged Access Management | In progress | CC6.3, CC6.1 | Service accounts for Google DWD per-org design |
| IAM-08 | Service Account & Infrastructure Credentials | Planned | CC6.1 | Session timeout policy documented |
| IAM-09 | Access Review Founder Attestation | Implemented | CC6.2, CC6.3 | MFA/auth policy covers password manager + unique creds |
| IAM-11 | Third-Party App & OAuth Integration Review | Planned | CC6.1, CC6.6 | API key lifecycle for future customer API |
INCIDENT RESPONSE
80% · 4 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| INC-01 | Incident Response Plan & Training | Implemented | CC7.4 | IR plan v0.1 |
| INC-02 | Incident Response Execution | Implemented | CC7.4, CC7.5 | Severity + response in IR plan |
| INC-03 | Incident Response Solo Operator | Implemented | CC7.4 | Customer/authority notify targets in IR plan |
| INC-04 | Post-Incident Review & Corrective Actions | Implemented | CC7.5 | Post-incident review in IR plan |
NETWORK & INFRASTRUCTURE
22.5% · 4 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| NET-01 | Network Isolation | In progress | CC6.1 | Platform network controls via Vercel/host |
| NET-02 | Boundary Protection | Planned | CC6.6 | WAF/rate limits on public endpoints |
| NET-03 | Physical Access Controls | Planned | CC6.4 | Segregation of prod/staging |
| NET-04 | Production Platform Hardening Managed Platforms | Planned | CC6.1 | Remote access policy |
PEOPLE
46% · 6 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| PPL-01 | Background Checks | In progress | CC1.4 | Onboarding via access policy + device checklist |
| PPL-02 | Job Descriptions & Competency | In progress | CC1.4 | AUP + security policy awareness for anyone with access |
| PPL-03 | Training & Competency Development | Planned | CC1.4, CC2.2 | Offboarding checklist |
| PPL-04 | Performance & Accountability | N/A | CC1.5 | No employees yet; disciplinary process when first hire |
| PPL-05 | Key Personnel & Continuity | Implemented | CC1.4 | Acceptable use policy v0.1 |
| PPL-06 | Contractor & Outsourced Personnel Controls | In progress | CC1.5 | Security requirements for contractors via AUP + agreements |
POLICY & DOCUMENTATION
80% · 3 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| HIP-03 | Security Documentation Retention | N/A | CC5.3 | HIPAA not in scope for current Canadian municipal GWS product wedge |
| POL-01 | Policy Suite & Governance | Implemented | CC5.3, CC3.1 | Information security policy v0.1 approved |
| POL-02 | Policy Communication & Accessibility | Implemented | CC2.2 | Public privacy policy live at /privacy |
PRIVACY
60.5% · 10 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| PRI-01 | Privacy Notice & Communication | Implemented | P1.1 | Purpose limitation in privacy policy + product design |
| PRI-02 | Consent Management | Implemented | P2.1 | DSAR playbook + internal lead inbox for controller data |
| PRI-03 | Personal Information Collection | Implemented | P3.1, P3.2 | Canadian privacy framing in policy + program docs |
| PRI-04 | Use & Purpose Limitation | Implemented | P4.1 | Retention schedule v0.1 |
| PRI-05 | Data Subject Access & Correction Rights | Implemented | P5.1, P5.2 | Deletion runbook v0.1 |
| PRI-06 | Disclosure & Third-Party Management | Implemented | P6.1, P6.2, P6.3, P6.4, P6.5 | Lead form privacy consent + policy link |
| PRI-07 | Privacy Breach Notification | Implemented | P6.6 | No employee password collection |
| PRI-08 | Data Subject Accounting Requests | Planned | P6.7 | Cross-border transfer assessment if any US subprocessors |
| PRI-09 | Data Quality | Planned | P7.1 | Privacy training for staff |
| PRI-10 | Privacy Monitoring & Dispute Resolution | Planned | P8.1 | Privacy impact assessment template for customers |
PROCESSING INTEGRITY
41% · 5 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| INT-01 | Processing Specifications & Requirements | Implemented | PI1.1 | Dry-run default + seat/campaign controls in product |
| INT-02 | Input Validation | Planned | PI1.2 | Data validation on imports/sync |
| INT-03 | Processing Accuracy & Completeness | Implemented | PI1.3 | Tenant isolation design + cross-tenant test plan |
| INT-04 | Output Controls | Planned | PI1.4 | Job completeness for sync/send |
| INT-05 | Data Storage Integrity | Planned | PI1.5 | Error handling SLAs |
RISK MANAGEMENT
47.5% · 2 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| RSK-01 | Annual Risk Assessment | Planned | CC3.1, CC3.2, CC3.3, CC3.4 | Annual risk assessment process |
| RSK-02 | Risk-Based Control Design | Implemented | CC5.1, CC5.2 | Risk tracked via go/no-go, SoA, remediation playbook |
SECURITY MONITORING
36.7% · 3 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| MON-01 | Security Logging | Planned | CC7.2 | Centralized app logging in production |
| MON-02 | Security Alerting & Event Triage | Planned | CC7.2, CC7.3 | Security alerting (failed auth, anomalous admin) |
| MON-03 | Security Logging Platform-Native | Implemented | CC7.2 | Admin audit log in product |
VENDOR MANAGEMENT
68.3% · 4 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| HIP-01 | Business Associate Agreements | N/A | CC9.2 | HIPAA BAA path not in current product scope |
| VND-01 | Vendor Risk Management | Implemented | CC9.2 | Vendor risk via policy, ISO control map, and contract control checklist |
| VND-02 | Subservice Organization Monitoring | In progress | CC9.2 | Annual vendor review in vendor policy |
| VND-04 | Subprocessor Change Management & Notification | Implemented | CC9.2 | Written notification process: 10 business day notice, objection window, changelog, public page, email template |
VULNERABILITY MANAGEMENT
25% · 3 controls
| ID | Control | Status | TSC | Notes |
|---|---|---|---|---|
| VUL-01 | Vulnerability Scanning | In progress | CC7.1 | npm audit in CI (high+) |
| VUL-02 | Penetration Testing | Planned | CC7.1 | Vulnerability remediation SLAs |
| VUL-04 | Dependency & Platform Update Management | Planned | CC7.1 | Penetration test before scale |
Evaluating PhishGuard?
We share this tracker, our security overview, and interim evidence pack on request — without pretending a certificate we do not have.
Control library © Chiaro methodology contributors · github.com/Chiaro-HQ/methodology · CC BY 4.0