DCdev4 Company· Trust Centre
All systems operational

dev4 Company
Trust Centre

Certifications

Independently audited

Click any certification to see scope, auditor and how to access the underlying report.

SOC2 POWERED BY SWISE

SOC 2

Issued by AICPA · Valid through 31 Aug 2026

AICPA Trust Services Criteria audit covering security, availability, processing integrity, confidentiality and privacy. Designed for SaaS and FinTech service providers — particularly those selling to North American enterprises.

AuditorAICPALast audit1 Jul 2026Valid until31 Aug 2026
Attachments
NISTCSF POWERED BY SWISE

NIST CSF 2.0

Issued by AICPA · Valid through 31 Dec 2026

The 2024 update to the NIST Cybersecurity Framework, adding Governance as a sixth core function alongside Identify, Protect, Detect, Respond, and Recover. A flexible, risk-based starting point for any organisation regardless of size or sector.

AuditorAICPALast audit1 Jul 2026Valid until31 Dec 2026
Attachments

The report is available on request.

Controls

Incident Recovery Plan Execution (RC.RP)

  • Post-Incident Operational Norms
  • Verification of Restoration Asset Integrity
  • Incident Recovery Documentation
  • Incident Response Recovery Plan Execution
  • Recovery Actions Selection and Prioritization
  • Verification and Restoration of Assets
View 1 more Incident Recovery Plan Execution (RC.RP) controls

Incident Recovery Communication (RC.CO)

  • Communication of Recovery Progress
  • Public Updates on Incident Recovery

Incident Management (RS.MA)

  • Incident Report Validation
  • Incident Recovery Criteria Application
  • Incident Categorization and Prioritization
  • Incident Response Coordination
  • Incident Escalation

Asset Management (ID.AM)

  • Asset Prioritization
  • Organizational Hardware Inventory Management
  • Organizational Software, Services, and Systems Management
  • Network Communication and Data Flow Maintenance
  • Supplier Services Inventory Management
  • Data and Metadata Inventory Management
  • Lifecycle Management of Systems and Assets
View 2 more Asset Management (ID.AM) controls

Incident Response Reporting and Communication (RS.CO)

  • Incident Notification to Stakeholders
  • Sharing Information with Stakeholders

Policy (GV.PO)

  • Enforcement of Cybersecurity Risk Policy
  • Cybersecurity Risk Management Policy

Awareness and Training (PR.AT)

  • Providing Awareness and Training for General Tasks
  • Providing Awareness and Training for Specialized Roles

Organizational Context (GV.OC)

  • Communication of Stakeholder Expectations
  • Aligned Cybersecurity with Mission
  • Stakeholder-Centric Cybersecurity Approach
  • Legal and Regulatory Cybersecurity Management
  • Organizational Dependency Understanding

Improvement (ID.IM)

  • Incident Response and Cybersecurity Plans
  • Security Tests and Exercises
  • Operational Processes
  • Identifying Improvements from Evaluations

Oversight (GV.OV)

  • Reviewing Cybersecurity Risk Strategy
  • Cybersecurity Strategy for Organization Needs
  • Evaluating Cybersecurity Risk Performance

Roles, Responsibilities, and Authorities (GV.RR)

  • Resources Aligned with Cybersecurity Strategy
  • Integration of Cybersecurity into HR Practices
  • Ethical Cybersecurity Leadership
  • Enforcement of Cybersecurity Responsibilities

Technology Infrastructure Resilience (PR.IR)

  • Resilience Mechanism Implementation
  • Resource Capacity Maintenance
  • Network and Environment Protection
  • Technology Asset Protection

Continuous Monitoring (DE.CM)

  • Computing Hardware and Software Monitoring
  • Network Event Monitoring
  • Physical Environment Monitoring
  • Personnel and Technology Event Monitoring
  • External Service Provider Monitoring

Data Security (PR.DS)

  • Protection of Data-at-Rest
  • Protection of Data-in-Transit
  • Protection of Data-in-Use
  • Management and Testing of Data Backups

Cybersecurity Supply Chain Risk Management (GV.SC)

  • Supplier Risk Assessment and Response
  • Supply Chain Security Practices
  • Integration of Supply Chain Risk Management
  • Post-Agreement Cybersecurity Risk Management
  • Risk Planning for Third-Party Relationships
  • Cybersecurity Risk Requirements in Supply Chain
  • Inclusion of Third Parties in Incident Planning
  • Cybersecurity Supply Chain Risk Management
  • Coordination of Cybersecurity Roles
  • Supplier Prioritization
View 5 more Cybersecurity Supply Chain Risk Management (GV.SC) controls

Incident Mitigation (RS.MI)

  • Incident Containment
  • Incident Eradication

Platform Security (PR.PS)

  • Maintenance of Software
  • Generation and Availability of Log Records
  • Configuration Management Practices
  • Maintenance of Hardware
  • Unauthorized Software Prevention
  • Secure Software Development Integration
View 1 more Platform Security (PR.PS) controls

Risk Management Strategy (GV.RM)

  • Aligning Organizational Cybersecurity Objectives
  • Communicating Risk Appetite and Tolerance
  • Integrating Cybersecurity into Risk Processes
  • Strategic Cybersecurity Response
  • Communication for Cybersecurity Risks
  • Standardize Cybersecurity Risk Prioritization
  • Strategic Opportunities in Cybersecurity Discussions
View 2 more Risk Management Strategy (GV.RM) controls

Incident Analysis (RS.AN)

  • Preservation of Incident Data
  • Estimation of Incident Magnitude
  • Incident Analysis & Root Cause Establishment
  • Integrity of Investigation Records

Risk Assessment (ID.RA)

  • Vulnerability Disclosure Response Processes
  • Hardware and Software Integrity
  • Assessment of Critical Suppliers
  • Management of Changes and Exceptions
  • Assessment of Threat Impacts and Likelihoods
  • Identification of Vulnerabilities
  • Receipt of Cyber Threat Intelligence
  • Identification of Internal and External Threats
  • Inherent Risk and Prioritizing Responses
  • Prioritizing and Planning Risk Responses
View 5 more Risk Assessment (ID.RA) controls

Identity Management, Authentication, and Access Control (PR.AA)

  • Identity Assertions Verification
  • User, Service, and Hardware Identities
  • Proofing and Binding Identities to Credentials
  • Authentication of Users, Services, and Hardware
  • Management of Access Permissions
  • Management of Physical Asset Access
View 1 more Identity Management, Authentication, and Access Control (PR.AA) controls

Adverse Event Analysis (DE.AE)

  • Potential Adverse Event Analysis
  • Cyber Threat Integration
  • Adverse Event Information Provision
  • Information Correlation
  • Impact and Scope Understanding
  • Incident Declaration
View 1 more Adverse Event Analysis (DE.AE) controls
Compliance scope

Which products are covered?

Here you'll find which certifications apply to each dev4 Company product. Cells marked N/A are out of scope; In progress means an audit is currently underway.
ProductSOC 2NIST CSF
Webapp
API
IAC
Resources

Documents & reports

Public documents are downloadable directly. Sensitive reports are released via an access request — usually approved within one business day.

📄
Compliance
Screenshot 2025-12-03 at 3.54.png
1.9 MB 🌐 Public
📄
Compliance
Screenshot 2025-11-17 at 10.51.png
124.5 KB 🔒 Request only
FAQ

Common questions

Answers to the questions we receive most often during security reviews.

What is security
Security is protection

Request access