SOC 2 Type IIon-track
Trust services criteria for the federation control plane.
last assessed 2026-06-30
| Control | Status | Evidence |
|---|---|---|
| CC7.2Incident response | passing |
|
| CC8.1Change management | passing |
|
| CC6.1Logical access | warn |
|
| CC6.6Break-glass approval | passing |
|
Admin · Governance · Frameworks
The compliance frameworks the federation control plane maps to, each backed by control-level coverage. ISO 27001 is bound to the provider cert string so the register reads one source of truth, and the full evidence pack exports for an auditor without rebuilding it.
Trust services criteria for the federation control plane.
last assessed 2026-06-30
| Control | Status | Evidence |
|---|---|---|
| CC7.2Incident response | passing |
|
| CC8.1Change management | passing |
|
| CC6.1Logical access | warn |
|
| CC6.6Break-glass approval | passing |
|
Information security management system controls.
last assessed 2026-05-15
certISO 27001held by Meridian Capacity Co.
| Control | Status | Evidence |
|---|---|---|
| A.9Access control | passing |
|
| A.12.1Operational change | passing |
|
| A.18.1Sovereign data residency | manual |
|
PHI handling for the Briarcliff Health custodial engagement.
last assessed 2026-04-20
| Control | Status | Evidence |
|---|---|---|
| 164.312(a)Access control (PHI) | passing |
|
| 164.308(a)Workforce security | warn |
|
| 164.502(e)Business associate | passing |
|