Access should be limited to only those with a legitimate business need and granted based on the principle of least privilege.
Security controls should be implemented and layered according to the principle of defense-in-depth.
Security controls should be applied consistently across all areas of the enterprise.
The implementation of controls is iterative, continuously maturing across the dimensions of improved effectiveness, increased auditability, and decreased friction.
SponsorUnited maintains a SOC 2 Type II attestation and a GDPR compliance certification. Our SOC 2 Type II report and GDPR compliance policy are available here.
SponsorUnited engages with testing consulting firms annually. Our current preferred penetration testing partner is Rhymetec. All areas of the SponsorUnited product and cloud infrastructure are in-scope for these assessments, and source code is fully available to the testers in order to maximize the effectiveness and coverage. We make summary penetration test reports available upon request.
SponsorUnited requires vulnerability scanning at key stages of our Secure Development Lifecycle (SDLC):
