This matrix aligns MarketMind AI's cloud infrastructure, security controls, and operational policies with the AICPA SOC 2 Trust Services Criteria.
Last updated: August 2026
CC6: Logical & Physical Access — Access restrictions, credential management, least privilege.
CC7: System Operations — Vulnerability monitoring, incident detection, anomaly alerts.
CC8: Change Management — Version control, testing, deployment safety.
Infrastructure Resilience — Uptime, disaster recovery, capacity management.
Data Protection & Disposal — Encryption, tenant segregation, secure purging.
AI Output Validity & Execution — Input validation, pipeline completeness, error handling.
Data Usage & Rights — Notice, choice, usage limits, zero training.
Physical, environmental, and hypervisor controls are inherited directly from Google Cloud Platform's SOC 2 Type II, ISO/IEC 27001, and HIPAA BAA-eligible frameworks. MarketMind AI itself is not currently HIPAA-compliant.
MarketMind AI is configured via Infrastructure as Code (Terraform) to enable automated continuous compliance tracking (via platforms like Vanta or Secureframe) ahead of a formal SOC 2 Type I audit post-seed round.
We use cookies
We use essential cookies to make our site work, and optional analytics cookies to understand how you use it. See our Privacy Notice and Terms.