Plurilock Security Inc. (TSX-V:PLUR), an identity-centric cybersecurity solutions provider, said that it has completed a SOC 2 assessment, successfully demonstrating it has effective controls in place for its cybersecurity solutions, business operations procedures, and tech infrastructure.
SOC 2 is a compliance standard for service organizations, developed by the American Institute of Certified Public Accountants, which specifies how organizations should manage customer data. It is based on five trust services criteria: security, availability, processing integrity, confidentiality, and privacy.
Before a company can undergo the SOC 2 audit, it needs to make another choice: a Type I, or comprehensive Type II audit.
READ: Plurilock receives purchase orders worth US$326,000 from US Marshals Service and US Drug Enforcement Administration
Plurilock received the results of a SOC Type II report after an assessment conducted by security and compliance firm BARR Advisory from June 1, 2021 to August 31, 2021.
During the assessment period, BARR reviewed access controls to Plurilock's systems, including its ADAPT and DEFEND authentication products, as well as the operating effectiveness of its infrastructure and internal and external controls, said the company.
By meeting the SOC Type II compliance standard, Plurilock said it has shown “there are controls and policies in place that mitigate risk,” as well as provide business continuity and customer assurance that systems and data will be protected.
The SOC Type II compliance validates Plurilock's role as a trusted third-party vendor for enterprise organizations within government, finance, healthcare, and education verticals, at a time when 51% of organizations have experienced a data breach caused by a third party.
Significantly, Plurilock has committed to only working with third-party vendors that also maintain SOC Type II compliance or equivalent controls. “Plurilock utilizes Amazon Web Services, further reducing risk by benefiting from their strong infrastructure controls,” said the company.
"It is paramount to maintain our clients' trust and demonstrating our SOC Type II compliance with this report affirms that their data and key resources are secured without compromising business continuity," Plurilock CEO Ian L. Paterson said in a statement. "This assessment is part of our ongoing efforts to provide top-notch cybersecurity continuous authentication solutions that are credible and well-recognized in the industry."
Plurilock's ADAPT solution provides multi-factor authentication for login or credential workflows, providing an additional, invisible authentication factor using behavioral biometrics, while reducing two-factor authentication prompts. On the other hand, Plurilock's DEFEND product is a continuous authentication platform that offers identity assurance and compromise detection, alerting IT security personnel to potential threats in real-time.
The company said it will revisit the SOC Type II compliance process on a yearly basis.
Contact the author Uttara Choudhury at uttara@proactiveinvestors.com
Follow her on Twitter: @UttaraProactive