Compliance and Certification
Solid's SOC 2 Type II certification, penetration testing, and the advanced threat protection controls behind it.
Certifications
- SOC 2 Type II Certified — independent validation of the security, availability, and confidentiality of the Solid platform.
- Annual external penetration tests — conducted by third-party security firms following OWASP WSTG 4.2 methodologies, including tenant-isolation attack simulations.
Advanced Threat Protection
| Control | Description |
|---|---|
| Supply chain scanning | Continuous scanning of open-source components and Infrastructure-as-Code (IaC) for known vulnerabilities |
| Code scanning | All code and infrastructure continuously scanned as part of the CI/CD pipeline |
| SIEM detection | Anomaly detection mapped to the MITRE ATT&CK framework |
| Endpoint protection | Corporate workstations protected by managed endpoint detection and response (EDR) |
| Audit logging | The platform emits standards-based (OpenTelemetry-compatible) audit and observability telemetry, supporting SIEM and log-aggregation integrations |
Specific tooling and vendor detail is available on request as part of a security review.
Updated 11 days ago
Did this page help you?
