Trust Center - Lithic
Security at Lithic
Security is fundamental to how Lithic builds and operates its platform. We design every system with protection, resiliency, and transparency at the forefront. Our security program aligns with SOC 1, SOC 2, ISO 27001, and PCI DSS, ensuring rigorous controls, continuous monitoring, and independent audits across all critical functions. We maintain strict access governance, thorough risk assessments, and a unified control framework to safeguard sensitive data. Protecting customer information isn’t just a requirement for Lithic, it is a core principle that guides every aspect of our operations.
Compliance
PCI DSS - SAQ D, SP and ROC Prep
ISO 27001:2022
SOC 2
SOC 1
Resources
- Lithic 2026 PCI DSS AOC Final Report.pdf
- PCI Responsibility Matrix.pdf
- POL318 Backup and Retention Policy.pdf
- POL315 Human Resource Security Policy.pdf
- POL308 Security and Privacy Awareness Policy.pdf
- POL304 Mobile Device Security Policy.pdf
- POL530 Logical Software Installation Policy.pdf
- POL306 Vulnerability Management Policy.pdf
- POL307 Logging and Monitoring Policy.pdf
- POL515 Threat Management Policy.pdf
Controls
Infrastructure security
- Remote access MFA enforced
- Remote access encrypted enforced
Product security
- Control self-assessments conducted
Internal security procedures
- Development lifecycle established
- Management roles and responsibilities defined
- Incident response policies established
Data and privacy
- Data retention procedures established
- Data classification policy established
Data collected
- Customer personally identifiable information
- Credit card information
Vanta connects to a company's core systems to continuously monitor these controls.