SOC 2 Type II
Independent controls attestation. Review the current scope, period, and supporting material.
Open Trust CenterA concise route into Gateway’s security approach, shared-responsibility model, and current diligence material. Exact controls depend on the service and deployment boundary.
Current certifications and attestations, with scope, period, and reports available through the Trust Center.
Independent controls attestation. Review the current scope, period, and supporting material.
Open Trust CenterInformation-security management. Review the current scope, period, and supporting material.
Open Trust CenterIndependent financial assurance. Review the current scope, period, and supporting material.
Open Trust CenterSecurity review starts with scope, then connects the operating boundary to current evidence and explicit customer controls.
Identify the Gateway service, deployment model, data classes, integrations, and operating parties in scope.
Record access, administration, keys, hosting, monitoring, incident, recovery, and customer responsibilities.
Confirm the legal entity, service, reporting period, exceptions, and available diligence material.
Carry provider, Gateway, and customer responsibilities into the applicable service and operating documents.
Review the current report, certificate, policy, scope, period, exceptions, and complementary customer controls before relying on an assurance item.
The applicable practices are selected and evidenced against the contracted service boundary rather than presented as universal claims.
Need the deeper model for enforcement points, evidence, deployment, privacy, and responsibility?
Review control architectureMap the deployment, enforcement points, evidence needs, provider roles, recovery behaviour, and residual risk.
Thank you