Skip to content

Security

The control posture of a firm that sells control environments.

If we were careless here, nothing else on this site would be worth reading. This page states what we design to, what we run ourselves, who attests to it, and what is still open.

Frameworks

What we design to.

Four frameworks, used for different jobs. None of them is invoked as a badge; each one answers a specific question about how a system should be built.

Frameworks in use

  • CC6.1SOC 2 Trust Services CriteriaThe control set every system is designed against. Security throughout, with availability and confidentiality criteria applied where a system holds investor or deal data.
  • NIST-PRNIST Cybersecurity Framework 2.0Used to structure the safeguards themselves across govern, identify, protect, detect, respond and recover, so a control gap shows up as a missing function rather than a missing document.
  • COBIT-APO13COBIT 2019Used for governance and management objectives: who owns a decision, what evidence that decision produces, and how risk appetite is expressed in a system rather than a statement.
  • COBIT-BAI06ITIL 4 practicesChange enablement, incident management and service continuity, adapted to a firm that has an operations lead rather than an operations department.

Designing to a framework is not the same as being certified against one. Exalto describes its systems as designed to the SOC 2 Trust Services Criteria. It does not describe them, or itself, as SOC 2 certified or SOC 2 compliant, and it uses no AICPA or SOC service marks.

Our own posture

What we run, and what is still open.

The same register format we would hand a client, applied to this firm. One row is open, and it stays open until the work behind it is done.

Exalto control posture

  • CC6.2EvidencedLeast-privilege access, reviewed on a scheduleAccess is granted by role, multi-factor authentication is mandatory, and joiner-mover-leaver changes are recorded where they happen rather than reconstructed afterwards.
  • CC6.7EvidencedClient data segregated and encryptedEncrypted in transit and at rest, segregated by engagement, and retained only as long as the engagement and our record-keeping obligations require.
  • CC7.4EvidencedDefined incident responseA written response process with named roles and a notification commitment, exercised rather than filed.
  • A1.3EvidencedRecovery tested, not assumedBackups are verified by restoring from them on a schedule, and the restore result is retained as the evidence that the control operated.
  • CC9.2OpenSubprocessor registerA current, published list of subprocessors with what each one processes. This is genuinely outstanding rather than merely unwritten, and it is marked open until it is published.

Independent attestation

Somebody else checks our work.

Exalto’s own control environment is independently attested by BetterLeg. They are a separate firm with no interest in what we build, which is the only arrangement under which an attestation means anything.

{{TODO: CLIENT INPUT}} Confirmation of how the BetterLeg relationship should be described, the scope and period of the attestation, and whether Henry Maphosa may be named on this page.

How independence works

We build to the framework. An independent firm attests.

Maxim is a CPA who has signed SOC 2 Type 2 opinions since 2002. That is exactly why Exalto will not audit what Exalto builds. Independence rules prohibit attesting to your own work, and an engagement structured that way would be worth nothing to the LP it was meant to satisfy.

What Exalto does

  • CC5.3EvidencedDesign the control environmentControls are specified against SOC 2 Trust Services Criteria, COBIT, ITIL and NIST CSF before the first schema is written.
  • CC5.2EvidencedBuild the system that enforces themSegregation of duties lives in the permission model. Approval chains live in the workflow. Neither lives in a policy document.
  • CC2.1EvidencedProduce the evidence continuouslyThe system generates the audit trail as work happens, so the evidence exists before anyone asks for it.

What Exalto never does

  • CC4.1OpenAudit or attest to its own workExalto issues no opinion, certificate or attestation on any system it has designed or built. Not on the same engagement, and not on a later one.
  • CC9.2OpenAct as your independent assessorAttestation is performed by a separate firm that you engage directly. Exalto’s own control environment is independently attested by BetterLeg.

Exalto does not describe itself, or anything it builds, as SOC 2 certified or SOC 2 compliant. A system is designed to the criteria; a firm is attested by an independent auditor. Anyone who blurs those two things is telling you something about how they work.

Data handling

Where data sits and who touches it.

Data residency

Client data for Canadian engagements is intended to remain in Canadian regions. This is stated as intent rather than as fact until the deployment regions are confirmed for each service.

{{TODO: CLIENT INPUT}} Confirmation of data residency: which regions client data is stored and processed in, per service.

Subprocessors

Every third party that processes client data on our behalf, what they process, and where. Published in full rather than summarised, because a summarised subprocessor list is not one.

{{TODO: CLIENT INPUT}} Subprocessor list: vendor, purpose, data categories processed, and hosting region for each.

This website

What this site does not do.

The privacy posture of a marketing site is a reasonable proxy for how a firm treats data it cares about more. Ours is deliberately unremarkable.

  • No Google Analytics, no advertising pixels and no session recording. Analytics, where used, is a privacy-first provider that sets no cookies and builds no cross-site profile.
  • No third-party cookies. Nothing on this site tracks you to another one.
  • No browser storage. The readiness scan holds your answers in memory for the length of the session and writes nothing to your device. Closing the tab discards them.
  • Scan results are shown in full before any email address is requested, and the assessment is never held back pending a form.

Security contact

Report a vulnerability or ask a security question at security@exaltoventures.ca. Reports are acknowledged, and we will not threaten anyone who reports something in good faith.

Run the same register over your own firm.

The readiness scan produces this format for your operations. Ungated, and nothing is stored.