Skip to main content

Security posture

Controls are useful when the evidence survives review.

IT Modality operates a risk-based security program for consulting, managed delivery, Academy, and operating-system services. Scope and access are bounded before work begins; evidence remains tied to an owner, period, and review path.

ForPeople conducting policy, privacy, security, or access review

FocusControls, ownership, evidence, and review paths

Independent assurance

Table — scroll horizontally to review every column.

EvidenceCurrent recordReview path
SOC 2 Type II reportApril 1, 2025 through March 31, 2026; issued May 2026Available through approved diligence
Third-party penetration testCompleted April 2026; annual cadenceExecutive summary available through diligence
Technology E&O insurance$5 millionCertificate available through diligence
Cyber liability insurance$5 millionCertificate available through diligence

Control families

  • Identity and least-privilege access with named owners and exit dates.

  • Environment, tenant, and client-data separation.

  • Encryption in transit and at rest, with key-custody boundaries.

  • Secure change, dependency, testing, and release controls.

  • Central telemetry, security-event review, and incident escalation.

  • Backup, restore, retention, deletion, and continuity exercises.

  • Provider due diligence, contractual controls, monitoring, and exit planning.

  • Human decision custody for clinical, legal, financial, and other consequential outcomes.

Incident record

Two severity-two incidents occurred, in 2021 · 2024. Both were contained, communicated to affected clients, closed with corrective action, and reviewed for control changes. Open severity-two incidents: 0.

Inspect the detailed security standard

Start a diligence conversation.