Compliance and Certification

Solid's SOC 2 Type II certification, penetration testing, and the advanced threat protection controls behind it.

Certifications

  • SOC 2 Type II Certified — independent validation of the security, availability, and confidentiality of the Solid platform.
  • Annual external penetration tests — conducted by third-party security firms following OWASP WSTG 4.2 methodologies, including tenant-isolation attack simulations.

Advanced Threat Protection

ControlDescription
Supply chain scanningContinuous scanning of open-source components and Infrastructure-as-Code (IaC) for known vulnerabilities
Code scanningAll code and infrastructure continuously scanned as part of the CI/CD pipeline
SIEM detectionAnomaly detection mapped to the MITRE ATT&CK framework
Endpoint protectionCorporate workstations protected by managed endpoint detection and response (EDR)
Audit loggingThe platform emits standards-based (OpenTelemetry-compatible) audit and observability telemetry, supporting SIEM and log-aggregation integrations

Specific tooling and vendor detail is available on request as part of a security review.


Did this page help you?