Skip to content

Security

Built for the audit you have not scheduled yet

Least privilege by default, every read logged, and the controls documented in a way your auditor can actually verify.

Security

Controls your auditor can test

Every control below maps to a clause and produces exportable evidence, because an assertion in a PDF is not a control.

SOC 2 CC6.1

Least privilege by default

A new user can read nothing. Access is granted per ledger and expires unless it is renewed.

SOC 2 CC7.2

Every read is logged

Not just writes. Who looked at which ledger, when, and from where, retained for seven years.

ISO 27001 A.10

Encrypted with your keys

Bring your own KMS key. Revoke it and the data is unreadable, including to us, within the hour.

GDPR Art. 44

Data residency

EU, UK, US or Australia. Data does not leave the region you pick, including backups and logs.

SOC 2 Type II

Evidence, not assertions

Control evidence is exportable on demand, so your auditor tests the system rather than reading our description of it.

SOX 404

Segregation of duties

The person who creates an adjustment cannot approve it. Enforced in the data model, not in a policy document.

Questions

What finance teams ask first

Most processors and banks are a credential and a callback, so under an hour. A custom or in-house ledger is a file format we map for you, which is typically two or three days including the test cycle you will want to run against historical data.

Contact

See it against your own data

Thirty minutes with an engineer and a sample of your ledger. We will show you the breaks you have today, or tell you that you have none — which does happen, and we will say so.

Sales

sales@cirrus.finance

Security

security@cirrus.finance

Trust centre

trust.cirrus.finance

Offices

London · New York · Singapore