8.7 C
New York
Wednesday, March 12, 2025

Rockset Is Now SOC 2 Sort II Compliant


The Rockset crew is proud to announce that we’ve got been accredited as SOC 2 Sort II compliant. Our prospects entrust Rockset with their information, and now they’ve rigorous, impartial assurance that we defend it by following safety greatest practices.

What’s SOC 2 Sort II?

SOC is one in all a number of System and Group Controls audits developed by the American Institute of CPAs (AICPA), the world’s largest member affiliation of accountants. Every SOC take a look at evaluates the validity of a enterprise or service supplier’s safety controls and the operational effectiveness of their techniques.

SOC checks differ considerably, nonetheless. In line with Forbes journal, SOC 2 “is essentially the most thorough and extensively valued of the three SOC experiences,” and the Sort II accreditation requires “a much more in-depth evaluation” of our information safety protocols than the Sort I. And MPA (Mortgage Skilled America) journal calls SOC 2 Sort II “among the many most coveted and arduous to acquire information-security certifications.”

By attaining SOC 2 Sort II compliance, Rockset was capable of show that our info safety and information insurance policies, procedures, and practices will defend our buyer’s information. It reveals that we’ve taken the right steps to make sure that information is safe.

Scope

What was included within the audit? At a excessive stage, Rockset was assessed on the themes of Safety, Confidentiality and Availability for the technical infrastructure and firm processes required to provide and help our SaaS service.

  • Change administration:
    Updates to the infrastructure, software, UI and API are linked to documented necessities, and merging of latest code requires peer evaluation.
  • Secrets and techniques administration:
    Encryption keys, passwords and different secrets and techniques are saved securely in access-controlled vaults with permission granted solely on a necessity foundation.
  • Metrics-based alerting:
    Operational efficiency information feeds into real-time dashboards and alerting techniques.
  • Safety monitoring:
    Alerts are despatched to the safety crew on a variety of occasions, together with uncommon outbound connections, anomalous authentication occasions, and suspicious server processes.
  • Hiring, onboarding and off-boarding processes:
    The Individuals Group ensures the talents and abilities of latest hires match the necessities of every open place, conducts screenings through the hiring course of, requests applicable accesses primarily based on position, and ensure these accesses are eliminated when personnel depart the corporate.
  • Entry controls:
    Entry is granted to firm sources primarily based on position, and are reviewed on an ongoing foundation.
  • Vulnerability administration:
    Rockset conducts common Third-party penetration checks and receives vulnerability experiences from impartial safety researchers on an ongoing foundation. Safety bugs are remediated by precedence and tracked to decision.

What Does This Imply for You?

For enterprises seeking to deliver on third-party service suppliers, Rockset’s SOC 2 Sort II compliance signifies a stage of course of maturity that minimizes danger and focuses on the safety of buyer information.

Rockset’s SOC 2 Sort II compliance signifies that our danger mitigation consists of the event of deliberate insurance policies, procedures, communications and various processing options to reply to and recuperate from any enterprise disruption. With this dedication, Rockset is ready to make sure the affect of any potential danger to our prospects is minimized.

If you wish to be taught extra about what SOC 2 Sort II accreditation means for you, take a look at this complete record from InfoSecurity Journal.

Our Dedication to Your Knowledge’s Safety and Privateness

Earlier than we even based Rockset, we knew that safety and compliance can be entrance and heart when it got here to constructing our information observability platform structure. In truth, safety runs in our DNA. A number of of us hail from cybersecurity suppliers like Palo Alto Networks and/or have cybersecurity certifications.

What’s Subsequent?

With SOC 2 Sort II, there is no such thing as a “resting in your laurels.” It’s an ongoing dedication. We’re continually striving to exceed the requirements, and regularly enhance our safety posture.

When you’ve got questions on Rockset’s SOC 2 Sort II compliance, attain out to our crew at [email protected]. To be taught extra about Rockset’s Safety Design, please go to: https://rockset.com/whitepapers/rockset-security-design


About Martin Englund

Martin Englund is the Info Safety Officer at Rockset and member of the Web site Reliability Engineering crew. He holds a CISSP certification and lives by the motto “The query is not for those who’re paranoid, it’s in case you are paranoid sufficient”.

Martin has over twenty 5 years of expertise in safety and automation, and has contributed to quite a few open supply DevOps instruments. Previous to his present position, he has labored as Web site Reliability Engineer at Palo Alto Networks and Manufacturing Engineer at Fb.

Earlier than switching fields to Web site Reliability Engineering, he was a Principal Safety Engineer at Solar Microsystems, the place he spent over fifteen years in numerous safety roles all through the corporate, co-authored the Solaris Safety Necessities guide, and authored a safety patent.



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles