Security

Certifications

We are constantly working hard to improve security at 21RISK. On this page you can read more about the external experts, that we pull in to make sure we do the job well.

SOC2 Type 2

We are excited to announce that 21RISK is now SOC 2 Type 2 certified!

SOC 2 (Service Organization Control Type 2) is a rigorous compliance standard that ensures the highest level of data security for organizations managing customer data in the cloud. This certification demonstrates our commitment to protecting the security, availability, processing integrity, confidentiality, and privacy of your data.

A SOC 2 report is a key document that showcases a company’s ability to effectively secure data. While SOC 2 Type 1 evaluates whether internal controls are properly designed, SOC 2 Type 2 goes a step further by assessing the operational effectiveness of these controls over time.

At 21RISK, we place the utmost importance on data security and client trust. As of January 2024, we have upgraded our systems to meet the stringent requirements of SOC 2 Type 2 certification. We are proud to confirm that we have successfully met all regulatory standards!

Note

As of August 2024 we at 21RISK have upgraded our security system, and we have obtained a SOC 2 Type 2 certification from Prescient Security !

Detectify scan

To keep 21risk.com safe, we have started an automated scans program with Detectify Detectify was founded in Stockholm Sweden, and is today 90+ SaaS security company.

We have configured Detectify to automatically scan our internet exposure every month

Here is the findings, from our latest report (2024 August)

For a full report, contact support@21risk.com .

HTTP header testing

For web-applications, http headers are one of the backbones for a secure environment. To test our headers, we use this tool . Here is the results from our latest test, August 2024.

Penetration testing

Note

We are currently in the process of finishing our first penetration test, with Cacilian as partner.