SOC 2 Type II
CompliantSecurity, availability and confidentiality controls, observed over a review period.
All mapped controls implemented, evidenced and monitored continuously.
Security · Privacy · Compliance
We operate a healthcare technology platform, so protected health information sits at the centre of our threat model. Every control, policy and task shown here is pulled live from the compliance system our security team runs — not a marketing snapshot.
2
Frameworks
actively monitored
35
Controls
mapped to requirements
25
Policies
published and in force
100%
Tasks complete
28 of 28 compliance tasks
2 tracked
Security, availability and confidentiality controls, observed over a review period.
All mapped controls implemented, evidenced and monitored continuously.
Administrative, physical and technical safeguards for protected health information.
All mapped controls implemented, evidenced and monitored continuously.
Documentation
Audit reports, security questionnaires and architecture summaries are released to customers and prospects after review by our security team. Requests are recorded in our compliance system and may require a signed NDA.
25 published
Acceptable Use & Workstation Security
Sets responsible use rules, enforces endpoint encryption, patching, auto-lock, and restricts personal storage of company data.
Access Control & Least Privilege
Implements a Joiner-Mover-Leaver workflow, role-based access control, quarterly reviews, and strict approval for elevated privileges.
Authentication & Password
Defines robust password rules, enforces MFA on sensitive systems, secures credential storage, and locks or resets risky accounts.
Background Screening & On/Off-boarding
Screens new hires, provisions least-privilege access, disables accounts and recovers assets at exit, and archives records securely.
Backup, Business Continuity & Disaster Recovery
Establishes backup frequency, off-site encrypted storage, quarterly restore tests, and concise BCP/DR activation playbooks.
Change & Release Management
Requires ticketed, peer-reviewed changes, pre-deployment testing, scheduled releases, emergency-change documentation, and post-release reviews.
Compliance & Regulatory Monitoring
Catalogues all legal, regulatory, and contractual obligations, links them to controls and evidence, and tracks enquiries and gaps to closure.
Data Classification & Handling
Uses a four-tier classification scheme to label data and prescribes access, encryption, sharing, and disposal rules for each level.
Encryption & Crypto Controls
Mandates strong encryption for data in transit and at rest, governs key generation, storage, rotation, and audits for weak configurations.
Incident Response & Breach Notification
Defines detection, triage, containment, communication, legal notification, and post-incident lessons with clear team roles.
Information Security & Privacy Governance
Assigns clear ownership and management accountability for security and privacy, keeps policies current, and measures compliance through regular reviews.
Information Sharing & Transfer
Restricts data transfers to approved encrypted channels, enforces NDAs and minimisation, records international safeguards, and audits transfer logs.
Logging, Monitoring & Audit
Centralises and protects logs, sets real-time alerting for critical events, retains audit trails, and reviews metrics and samples monthly.
Physical Security & Environmental
Controls facility and server-room access, manages visitors, safeguards against fire, flood, or climate risks, and audits logs and walk-throughs.
Policy Management & Exception Handling
Inventories every policy, enforces version control and annual reviews, and documents, time-boxes, and sunsets any approved exceptions.
Privacy & Data-Subject Rights
Ensures personal data is processed on a lawful basis, keeps users informed, and fulfils data-subject requests within required timelines.
Remote Access & BYOD
Approves secure VPN or zero-trust methods, sets endpoint hardening and mobile controls, and logs and reviews remote sessions.
Retention & Secure Disposal
Sets record-specific retention periods, runs periodic purge reviews, and requires cryptographic or physical destruction of outdated data.
Risk Management
Maintains a living risk register, scores and prioritises threats, sets treatment actions, and injects threat-intel updates into decision-making.
Sanctions & Disciplinary
Applies a progressive, documented disciplinary framework for security or privacy violations, ensuring fair process and consistent sanctions.
Secure Configuration & Hardening
Publishes baseline hardening guides, uses version-controlled IaC, detects configuration drift, and backs up critical configs.
Secure Software Development Lifecycle
Embeds security user stories, automated code scans, dependency checks, secrets detection, and pre-release penetration testing into every build.
Security & Privacy Awareness Training
Delivers onboarding and annual refresher training, role-based modules, simulated phishing, and tracks completion metrics.
Vendor & Third-Party Risk
Inventories vendors, tiers them by data impact, conducts due diligence, embeds security clauses in contracts, and monitors attestations and incidents.
Vulnerability & Patch Management
Runs routine scans, prioritises patches by CVSS and exploit activity, enforces remediation SLAs, and verifies closure.
Policy documents themselves are available under the document request process above.
Our security team monitors this inbox directly. Vulnerability reports are triaged within one business day.
support@ankr.us