Skip to main content

SOC 2 Controls Mapping

This document maps all Devotel technical controls to the AICPA SOC 2 Trust Services Criteria. Each control is linked to the relevant infrastructure, application, or operational mechanism within the Devotel CPaaS platform.

Security (CC6) — Common Criteria

CC6.1 — Logical Access Controls

The entity implements logical access security measures to protect against unauthorized access.

CC6.2 — Boundary Protection

The entity implements controls to protect system boundaries and restrict unauthorized network access.

CC6.3 — Encryption

The entity implements encryption to protect data at rest and in transit.

CC6.6 — System Monitoring

The entity implements monitoring to detect anomalies, vulnerabilities, and security events.

CC6.7 — Change Management

The entity implements controls over changes to system components.

Availability (A1)

A1.1 — Processing Capacity

The entity maintains, monitors, and evaluates current processing capacity and usage of system components to manage capacity demand.

A1.2 — Recovery

The entity authorizes, designs, develops, implements, operates, approves, maintains, and monitors environmental protections, software, data backup and recovery infrastructure, and plans to meet its objectives.

Confidentiality (C1)

C1.1 — Data Classification

The entity identifies and classifies confidential information.

C1.2 — Disposal

The entity disposes of confidential information to meet the entity’s objectives.

Evidence Collection

For audit purposes, the following evidence artifacts are available:
  1. Access Reviews — Export team members and roles via GET /api/v1/settings/team
  2. Audit Log Export — Download audit logs via GET /api/v1/settings/audit-logs/export?format=csv&date_range=90d
  3. Change History — Git commit history and PR review records on GitHub
  4. PHI Access Log — Export PHI access log via GET /api/v1/settings/hipaa/phi-access-log
  5. API Key Inventory — List all API keys via GET /api/v1/settings/api-keys
  6. Infrastructure Configuration — Terraform state files and Kubernetes manifests in infrastructure/

Last reviewed: April 2026 Next review: July 2026