> ## Documentation Index
> Fetch the complete documentation index at: https://docs.condense.io/llms.txt
> Use this file to discover all available pages before exploring further.

# AICPA SOC 2

Zeliot Connected Services Pvt. Ltd. and the Condense platform maintain **SOC 2 compliance**, based on the **AICPA Trust Services Criteria**. SOC 2 provides an independent framework for evaluating controls relevant to the security, availability, processing integrity, confidentiality, and privacy of information and systems.

SOC 2 demonstrates Zeliot's commitment to maintaining effective controls for protecting customer information, securing platform infrastructure, and managing operational risks associated with the delivery of Condense.

### Overview of AICPA SOC 2

SOC 2 is an attestation framework developed by the **American Institute of Certified Public Accountants (AICPA)**. It evaluates an organization's controls against the AICPA Trust Services Criteria.

The Trust Services Criteria cover five areas:

* **Security**: Protection of systems and information against unauthorized access, disclosure, damage, or disruption.
* **Availability**: Controls supporting the availability and operational performance of systems as committed to customers.
* **Processing Integrity**: Controls designed to ensure that system processing is complete, valid, accurate, timely, and authorized.
* **Confidentiality**: Protection of information designated as confidential throughout its lifecycle.
* **Privacy**: Controls relating to the collection, use, retention, disclosure, and disposal of personal information.

The applicable Trust Services Criteria depend on the scope of the SOC 2 examination.

### SOC 2 and Condense

Condense is Zeliot's real-time data streaming and application platform, designed to support enterprise workloads that require reliable data movement and processing.

SOC 2 controls supporting Condense address relevant aspects of:

* Platform and infrastructure security
* Logical and physical access controls
* Protection of customer information
* System monitoring and operational controls
* Change management
* Risk management
* Incident response
* Availability and business continuity
* Vendor and third-party risk management
* Data protection and confidentiality

These controls form part of the processes used to develop, operate, monitor, and support the Condense platform.

### What SOC 2 Means for Condense Customers

For enterprises using Condense as part of their real-time data infrastructure, SOC 2 provides an independently assessed framework for understanding how controls are designed and operated to address relevant Trust Services Criteria.

This includes:

* **Security Controls** to protect systems and information from unauthorized access and other security threats.
* **Access Management** through defined processes for authentication, authorization, and management of access to systems and information.
* **Change Management** through controlled processes for changes to systems and platform components.
* **Monitoring and Incident Management** through processes for identifying, managing, and responding to security and operational events.
* **Availability Controls** supporting the reliable operation of systems and services within the applicable examination scope.
* **Data Protection** through controls designed to safeguard customer and confidential information.
* **Vendor Management** through processes for identifying and managing relevant risks associated with third-party service providers.

### SOC 2 Compliance

SOC 2 is maintained through a structured program of controls, monitoring, assessment, and continuous improvement.

Key activities include:

* Ongoing monitoring of security and operational controls
* Periodic risk assessments
* Access reviews
* Security and operational monitoring
* Incident management and response
* Change management
* Vendor and third-party risk management
* Business continuity planning
* Internal control reviews and remediation

The SOC 2 framework enables Zeliot to continuously assess and improve the controls supporting its products, services, and information security practices.

### Certification and Examination Details

SOC 2 is an **attestation report**, rather than an ISO-style certification. The specific SOC 2 report should be referenced for the applicable:

* **Report Type:** SOC 2 Type I or SOC 2 Type II
* **Examination Period:** Applicable reporting period
* **Trust Services Criteria:** Criteria included within the examination scope
* **Service Organization:** Zeliot Connected Services Pvt. Ltd.
* **System or Service:** Condense and applicable supporting systems
* **Independent Service Auditor:** As identified in the SOC 2 report

### Relationship to Other Certifications

SOC 2 complements Zeliot's **ISO 9001:2015 Quality Management System** and **ISO/IEC 27001:2022 Information Security Management System**.

Together, these frameworks support Zeliot's approach to quality management, information security, operational controls, and the secure delivery of Condense to enterprise customers.
