Compliance Roadmap
The practical path Just Scope IT is taking toward stronger third-party security assurance.
Last updated: July 27, 2026
Current Direction
- CurrentPublic Trust Center, Security Addendum, Privacy Policy, Fair Use Policy, and subprocessors information.
- In ProgressCSA STAR Level 1 self-assessment preparation using the CSA CAIQ and Cloud Controls Matrix.
- In ProgressSOC 2 readiness groundwork, including formal control documentation and evidence collection.
- In ProgressRoutine third-party penetration testing and customer-shareable remediation summary.
CSA STAR Level 1 Preparation
CSA STAR Level 1 is a self-assessment. Just Scope IT plans to complete the CAIQ honestly, using current, partial, and planned control notes rather than overstating maturity. Submission should happen after the package can stand up to a customer security review.
Evidence Being Prepared
- Production architecture diagram.
- Access control and MFA evidence for critical systems.
- Backup configuration and restore-test evidence.
- Vulnerability/dependency scan records.
- Change/deployment process evidence.
- Incident response process and contact path.
- Encryption, secrets handling, and tenant isolation notes.
- Vendor and subprocessor review notes.