SenraSenra
Trust Center

Your Organization

We take the security and privacy of our customers' data seriously. Here's how we protect it — our certifications and frameworks, the controls we run and monitor continuously, how we manage third parties, access, and risk, and the documentation available on request.

Controls

The controls we operate, grouped by family. 49 controls implemented and monitored.

CC6 - Logical & Physical Access

12
  • A user access review of network and application accounts, and associated permissions, is performed quarterly to ensure appropriate logical access is maintained.
  • Administrator access is limited to only authorized personnel.
  • Administrator access is limited to only authorized personnel.
  • Firewalls are in place to protect production systems and are configured to restrict unnecessary ports, protocols, and services. Logs are monitored to detect any potential security vulnerabilities or unauthorized access attempts.
  • Human Resources is responsible for notifying IT of terminated employees and contractors. IT terminates logical access within 24 hours of notification.
  • Human Resources is responsible for notifying IT of terminated employees and contractors. IT terminates logical access within 24 hours of notification.
  • Modified user access to the network and in-scope applications is authorized by appropriate personnel and granted based on job role via the access provisioning process. Role-Based Access Control (RBAC) is used to support segregation of incompatible functions.
  • New user access to the network and in-scope applications is authorized by appropriate personnel and granted based on job role via the access provisioning process. Role-Based Access Control (RBAC) is used to support segregation of incompatible functions.
  • Policies and procedures define requirements for granting, provisioning, and revoking access to data and systems. The assignments are role-based and are defined by management.
  • Separate environments are used for development, testing, and production. Changes require independent review and approval before they can be merged to production.
  • The Company has a documented Change Management Policy that addresses changes to system components, including those that may affect system security. Such changes require approval from IT management, or an authorized delegate, before implementation. The policy is reviewed annually.
  • Users are required to authenticate via unique user account ID and password before being granted access to in-scope networks, systems, and applications.

A.5 Organizational controls

9
  • Access control
  • Addressing information security within supplier agreements
  • Compliance with policies, rules and standards for information security
  • Information security in supplier relationships
  • Information security incident management planning and preparation
  • Information transfer
  • Learning from information security incidents
  • Privacy and protection of PII
  • Response to information security incidents

A.8 Technological controls

8
  • Installation of software on operational systems
  • Networks security
  • Privileged access rights
  • Secure authentication
  • Security testing in development and acceptance
  • Segregation of networks
  • Use of cryptography
  • User endpoint devices

6 Impact-assessment documentation

3
  • AI system purpose
  • Geography and language context
  • Impact analysis overview

CC5 - Control Activities

3
  • A formal Incident Management process is documented to define protocols for reporting potential security events, procedures for evaluating detected/reported security events, roles and responsibilities for managing security events, and escalation criteria to determine when to enact the Incident Response Plan.
  • Policies and procedures define requirements for granting, provisioning, and revoking access to data and systems. The assignments are role-based and are defined by management.
  • The Company maintains recovery strategies, such as data replication, onsite and offsite backups, and high availability strategies for critical data systems to assure the restoration of service.

CC7 - System Operations

3
  • A formal Incident Management process is documented to define protocols for reporting potential security events, procedures for evaluating detected/reported security events, roles and responsibilities for managing security events, and escalation criteria to determine when to enact the Incident Response Plan.
  • Detected and reported security events are logged in a ticketing system, evaluated, classified, and tracked through to resolution.
  • The technical security configuration of information systems and network components (e.g., firewalls, routers, switches) is reviewed for compliance with the configuration standards manually, by an individual with experience with the systems. These compliance checks are performed annually, at minimum.

6 Planning

2
  • AI system impact assessment
  • Planning AIMS changes

A.6 People controls

2
  • Confidentiality or non-disclosure agreements
  • Responsibilities after termination or change of employment

A.8 Information for interested parties

2
  • Information for interested parties
  • System documentation and information for users

CC2 - Communication & Information

2
  • Changes made to systems are communicated to appropriate users.
  • The Company has a comprehensive Incident Response Plan that is communicated to staff and is regularly updated. Incident response training is held annually.

CC8 - Change Management

2
  • Emergency changes are documented, authorized, tested, and approved following the Change Management Policy.
  • System changes are documented, tested, and approved prior to migrating the change to production as part of the change management process.

8 Operation

1
  • AIMS operational planning and control

© 2026 Your Organization · Powered by Senra