Security posture
Controls are useful when the evidence survives review.
IT Modality operates a risk-based security program for consulting, managed delivery, Academy, and operating-system services. Scope and access are bounded before work begins; evidence remains tied to an owner, period, and review path.
ForPeople conducting policy, privacy, security, or access review
FocusControls, ownership, evidence, and review paths
Independent assurance
Table — scroll horizontally to review every column.
| Evidence | Current record | Review path |
|---|---|---|
| SOC 2 Type II report | April 1, 2025 through March 31, 2026; issued May 2026 | Available through approved diligence |
| Third-party penetration test | Completed April 2026; annual cadence | Executive summary available through diligence |
| Technology E&O insurance | $5 million | Certificate available through diligence |
| Cyber liability insurance | $5 million | Certificate available through diligence |
Control families
Identity and least-privilege access with named owners and exit dates.
Environment, tenant, and client-data separation.
Encryption in transit and at rest, with key-custody boundaries.
Secure change, dependency, testing, and release controls.
Central telemetry, security-event review, and incident escalation.
Backup, restore, retention, deletion, and continuity exercises.
Provider due diligence, contractual controls, monitoring, and exit planning.
Human decision custody for clinical, legal, financial, and other consequential outcomes.
Incident record
Two severity-two incidents occurred, in 2021 · 2024. Both were contained, communicated to affected clients, closed with corrective action, and reviewed for control changes. Open severity-two incidents: 0.