# Security at Lithic

Security is fundamental to how Lithic builds and operates its platform. We design every system with protection, resiliency, and transparency at the forefront. Our security program aligns with SOC 1, SOC 2, ISO 27001, and PCI DSS, ensuring rigorous controls, continuous monitoring, and independent audits across all critical functions. We maintain strict access governance, thorough risk assessments, and a unified control framework to safeguard sensitive data. Protecting customer information isn’t just a requirement for Lithic, it is a core principle that guides every aspect of our operations.

## Compliance

- PCI DSS - SAQ D, SP and ROC Prep
- ISO 27001:2022

- SOC 2
- SOC 1

## Resources

- [Lithic 2026 PCI DSS AOC Final Report.pdf](https://trust.lithic.com/?requestAccessOpen=true&requestedResources=68f108384690cacc2d39d1e6)
- [PCI Responsibility Matrix.pdf](https://trust.lithic.com/?requestAccessOpen=true&requestedResources=68f10839921cb76d33f99395)
- [POL318 Backup and Retention Policy.pdf](https://trust.lithic.com/?requestAccessOpen=true&requestedResources=693c08e7365f7acfe56c4a9c)
- [POL315 Human Resource Security Policy.pdf](https://trust.lithic.com/?requestAccessOpen=true&requestedResources=693c08e74fbb762af9ed5793)
- [POL308 Security and Privacy Awareness Policy.pdf](https://trust.lithic.com/?requestAccessOpen=true&requestedResources=693c08e75629586a27307fda)
- [POL304 Mobile Device Security Policy.pdf](https://trust.lithic.com/?requestAccessOpen=true&requestedResources=693c08e7589c48b7b3a85f9c)
- [POL530 Logical Software Installation Policy.pdf](https://trust.lithic.com/?requestAccessOpen=true&requestedResources=693c08e745973c55263ce723)
- [POL306 Vulnerability Management Policy.pdf](https://trust.lithic.com/?requestAccessOpen=true&requestedResources=693c08e77b1e7d4094fe0f28)
- [POL307 Logging and Monitoring Policy.pdf](https://trust.lithic.com/?requestAccessOpen=true&requestedResources=693c08e77feb47ca86a97b81)
- [POL515 Threat Management Policy.pdf](https://trust.lithic.com/?requestAccessOpen=true&requestedResources=693c08e7e1de6fe3883d04f4)

## Controls

- **Infrastructure security**  
  - Remote access MFA enforced  
  - Remote access encrypted enforced

- **Product security**  
  - Control self-assessments conducted

- **Internal security procedures**  
  - Development lifecycle established  
  - Management roles and responsibilities defined  
  - Incident response policies established

- **Data and privacy**  
  - Data retention procedures established  
  - Data classification policy established

## Data collected

- Customer personally identifiable information  
- Credit card information

Vanta connects to a company's core systems to continuously monitor these controls.
