← Compliance / SOC 2

Address SOC 2 Trust Service Criteria for WordPress.

BlockForge provides built-in controls that map to SOC 2 Security, Availability, and Processing Integrity criteria. Continuous monitoring, encrypted backups, audit logging, and role-based access — ready for your next audit.

~90%

criteria coverage

Security

Strong

Availability

Strong

Integrity

Partial

Confidentiality

Partial

Security — Common Criteria

The Security category spans CC1 through CC9 and forms the foundation of every SOC 2 engagement. BlockForge addresses key criteria with built-in monitoring, access control, and incident response capabilities.

CC4.1

Monitoring & Reporting

Continuous monitoring with exportable audit reports in PDF and CSV. Compliance scoring, vulnerability scanning, and change detection with real-time alerting across all WordPress installations.

CC5.1

Control Activities

Automated security key rotation, malware scanning schedules, and backup verification workflows that enforce operational controls without manual intervention.

CC6.1

Logical Access & MFA

Role-based access control with granular permissions plus TOTP-based two-factor authentication with recovery codes, rate limiting, and password-protected disable.

CC6.6

System Boundaries

HMAC-SHA256 authenticated API communication between all system components. Every request between BlockForge and your WordPress sites is cryptographically signed and verified.

CC7.2

System Monitoring

Complete audit trail of all platform actions, external change detection with actor tracking. Every action is logged with timestamps, user identity, and context.

CC7.3

Event Detection

Multi-channel notifications (Email, Slack, Webhooks) with severity-based routing and critical event push. Configure escalation chains per site or globally.

CC7.4

Incident Response

WordPress broken detection with automated recovery, configurable escalation chains. When a site goes down or is compromised, BlockForge initiates response workflows automatically.

CC8.1

Change Management

Activity logging for all changes, staging environments for safe testing, and file integrity verification. Test updates in isolation before deploying to production.

Availability

The Availability criteria focus on system uptime, disaster recovery, and capacity management. BlockForge provides continuous monitoring, automated backups, and recovery validation.

A1.1

Capacity & Performance

Multi-probe uptime monitoring from distributed geographic locations, performance metrics tracking. Detect degradation before it becomes an outage.

A1.2

Recovery

Automated daily backups with dual-location storage, WordPress auto-healing after detected failures. Backups are encrypted with AES-256 and stored in geographically separate locations.

A1.3

Recovery Testing

Automated backup verification in isolated containers, restore capability validation. Every backup is tested to ensure it can actually be restored when needed.

Processing Integrity & Confidentiality

BlockForge provides partial coverage for Processing Integrity and Confidentiality criteria. These controls focus on data accuracy, completeness, and protection of sensitive information.

PI1 — Partial Coverage

Processing Integrity

Change detection ensures processing accuracy by identifying unauthorized modifications. The complete audit trail provides full traceability of every action performed on your WordPress infrastructure.

  • Change detection for processing accuracy
  • Full audit trail with traceability

C1 — Partial Coverage

Confidentiality

Sensitive data is protected with encryption at rest and in transit. Access is controlled through role-based permissions, and all API communication is cryptographically authenticated.

  • AES-256 encrypted backups
  • Role-based access controls
  • HMAC-signed API communication

Additional controls

Beyond the core criteria, BlockForge provides additional controls that strengthen your SOC 2 posture.

CC4.1

Security Posture Dashboard

Aggregated risk overview with compliance score distribution, category breakdown, and critical issues tracking across your entire workspace.

CC6.1

Session Management

Active session monitoring with configurable timeouts, individual and bulk session revocation, and device tracking for all platform users.

CC6.5

Data Retention Policies

Configurable retention periods for activity logs, uptime checks, security scans, and backups with automated data disposal and compliance tracking.

Other frameworks

BlockForge maps to multiple compliance frameworks. Explore how your WordPress infrastructure addresses each set of requirements.

Ready to address SOC 2 requirements?

Start mapping your WordPress infrastructure to SOC 2 Trust Service Criteria today. No credit card required.