# Security at Lithic

Security is fundamental to how Lithic builds and operates its platform. We design every system with protection, resiliency, and transparency at the forefront. Our security program aligns with SOC 1, SOC 2, ISO 27001, and PCI DSS, ensuring rigorous controls, continuous monitoring, and independent audits across all critical functions. We maintain strict access governance, thorough risk assessments, and a unified control framework to safeguard sensitive data. Protecting customer information isn’t just a requirement for Lithic, it is a core principle that guides every aspect of our operations.

## Controls

Updated 1 minute ago

### Infrastructure security

| Control | Status |
| --- | --- |
| Remote access MFA enforced<br>The company's production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method. |  |
| Remote access encrypted enforced<br>The company's production systems can only be remotely accessed by authorized employees via an approved encrypted connection. |  |

### Product security

| Control | Status |
| --- | --- |
| Control self-assessments conducted<br>The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings. If the company has committed to an SLA for a finding, the corrective action is completed within that SLA. |  |

### Internal security procedures

| Control | Status |
| --- | --- |
| Development lifecycle established<br>The company has a formal systems development life cycle (SDLC) methodology in place that governs the development, acquisition, implementation, changes (including emergency changes), and maintenance of information systems and related technology requirements. |  |
| Management roles and responsibilities defined<br>The company management has established defined roles and responsibilities to oversee the design and implementation of information security controls. |  |
| Incident response policies established<br>The company has security and privacy incident response policies and procedures that are documented and communicated to authorized users. |  |
| Risk management program established<br>The company has a documented risk management program in place that includes guidance on the identification of potential threats, rating the significance of the risks associated with the identified threats, and mitigation strategies for those risks. |  |
| Physical access processes established<br>The company has processes in place for granting, changing, and terminating physical access to company data centers based on an authorization from control owners. |  |
| Data center access reviewed<br>The company reviews access to the data centers at least annually. |  |

### Data and privacy

| Control | Status |
| --- | --- |
| Data retention procedures established<br>The company has formal retention and disposal procedures in place to guide the secure retention and disposal of company and customer data. |  |
| Data classification policy established<br>The company has a data classification policy in place to help ensure that confidential data is properly secured and restricted to authorized personnel. |  |

Vanta connects to a company's core systems to continuously monitor these controls.
