Security & Compliance

How We Approach Security

Practices we build into every engagement — not a certification badge, but how we actually design and operate systems.

IT-ISS does not currently hold formal third-party certifications such as SOC 2 or ISO 27001. The principles below describe the practices we apply to our own products and client engagements today.

🔒 Encryption at Rest & In Transit

Sensitive data encrypted in the database and in transit between services, applied consistently across the products we build and operate — including SPAM Escudo and Cerberus ID.

🔐 Least-Privilege Access Control

IAM roles, VPC segmentation, and Security Group hardening scoped down to the individual role and resource, not broad standing access.

🧩 PII Minimization

No personal data retained beyond what a decision or feature strictly requires — a first-class architectural requirement in products like SPAM Escudo and Cerberus ID, not an afterthought.

🌐 GDPR/CCPA-Aware Architecture

Data handling designed around GDPR and CCPA localization and retention requirements from the start, rather than bolted on after the fact.

🧲 Patch & Vulnerability Management

Scheduled OS and database patching, and version upgrades, handled on a planned cadence as part of our managed-services work.

🧪 Backup Verification & DR Drills

Proving that backups actually restore — not just that they run — through scheduled recovery drills against real DR runbooks.

Have specific compliance requirements? Get in touch →