SOC 2 control matrix
Trust Services Criteria mapped to shipped Bacenik CIQ™ controls. This is not a SOC 2 report — independent assessment remains External until an auditor report is linked.
| TSC | Control | Evidence | Status |
|---|---|---|---|
| CC6.1 | Logical access — company sign-in, two-factor, and roles | Signed sessions, two-factor for approvers, company sign-in and directory sync when enabled | Implemented |
| CC6.6 | Encryption in transit and secrets at rest | TLS in transit; secrets stored encrypted | Implemented |
| CC7.2 | System monitoring | Public service status page and health checks | Implemented |
| CC8.1 | Change management / audit | Tamper-evident audit trail | Implemented |
| A1.2 | Backup and recovery | Requires confirmed backup and restore evidence — not automatic | Documented |
| P1.1 | Privacy notice / DPA | Data Processing Addendum and subprocessors (templates) | Documented |
| C1.1 | Confidentiality — tenancy isolation | Organization isolation tests | Implemented |
| CC9.1 | Vendor management | Published subprocessors · ciq-erp-cert-2026.07 | Documented |
| CC4.1 | Independent assessment | No auditor report linked — do not claim SOC 2 certification | External |