| 12.10.3 | Xactus | Vanta Trust Center | documented | - | - |
| 12.10.4 | Xactus | Vanta Trust Center | documented | - | - |
| 12.10.4.1 | Xactus | Vanta Trust Center | documented | - | - |
| 12.10.5 | Xactus | Vanta Trust Center | documented | - | - |
| 12.10.6 | Xactus | Vanta Trust Center | documented | - | - |
| 12.10.7 | Xactus | Vanta Trust Center | documented | - | - |
| 12.2 Acceptable use policies for end-user technologies are defined and implemented. | Staq.io | Vanta Trust Center | documented | - | - |
| 12.2.1 | Xactus | Vanta Trust Center | documented | - | - |
| 12.3.1 | Xactus | Vanta Trust Center | documented | - | - |
| 12.3.2 | Xactus | Vanta Trust Center | documented | - | - |
| 12.3.3 | Xactus | Vanta Trust Center | documented | - | - |
| 12.3.4 | Xactus | Vanta Trust Center | documented | - | - |
| 12.4 PCI DSS compliance is managed. | Staq.io | Vanta Trust Center | documented | - | - |
| 12.5.1 | Xactus | Vanta Trust Center | documented | - | - |
| 12.5.2 | Xactus | Vanta Trust Center | documented | - | - |
| 12.7 Personnel are screened to reduce risks from insider threats. | Staq.io | Vanta Trust Center | documented | - | - |
| 12.7.1 | Xactus | Vanta Trust Center | documented | - | - |
| 12.8.1 | Archon Systems | Vanta Trust Center | documented | - | - |
| 12.8.1 | Xactus | Vanta Trust Center | documented | - | - |
| 12.8.1 | Neuro | Vanta Trust Center | documented | - | - |
| 12.8.2 | Archon Systems | Vanta Trust Center | documented | - | - |
| 12.8.2 | Xactus | Vanta Trust Center | documented | - | - |
| 12.8.3 | Neuro | Vanta Trust Center | documented | - | - |
| 12.8.3 | Xactus | Vanta Trust Center | documented | - | - |
| 12.8.3 | Archon Systems | Vanta Trust Center | documented | - | - |
| 12.8.4 | Xactus | Vanta Trust Center | documented | - | - |
| 12.8.4 | Archon Systems | Vanta Trust Center | documented | - | - |
| 12.8.5 | Archon Systems | Vanta Trust Center | documented | - | - |
| 12.8.5 | Xactus | Vanta Trust Center | documented | - | - |
| 12.9 Third-party service providers (TPSPs) support their customers’ PCI DSS compliance. | Staq.io | Vanta Trust Center | documented | - | - |
| 13 + 48 - System changes communicated | Snappy | Vanta Trust Center | documented | - | - |
| 15 - Support system available | Snappy | Vanta Trust Center | documented | - | - |
| 17.1 High-Risk AI Quality Management System | Maywood AI | Vanta Trust Center | documented | - | - |
| 17.1 High-Risk AI Quality Management System | HeyJobs | Vanta Trust Center | documented | - | - |
| 17a-4 WORM, CFTC 1.31, and MiFID II Compliance | Theta Lake | SafeBase | documented | - | - |
| 1EdTech Data Privacy Certification | Macmillan | SafeBase | documented | - | - |
| 1Password 2025 Annual Pentest | 1Password | SafeBase | documented | - | - |
| 2 - Management roles and responsibilities defined | Snappy | Vanta Trust Center | documented | - | - |
| 2 - SOC 2 Type 2 + HIPAA Report | Gong | SafeBase | documented | - | - |
| 2 consumer requests free | Position Imaging Inc. | Vanta Trust Center | documented | - | - |
| 2 consumer requests free | Osta | Vanta Trust Center | documented | - | - |
| 2 consumer requests free | RevOptimal | Vanta Trust Center | documented | - | - |
| 2 consumer requests free | Community Boss | Vanta Trust Center | documented | - | - |
| 2-Factor Authentication | GitLab | SafeBase | documented | - | - |
| 2-Factor Authentication | Homebase | SafeBase | documented | - | - |
| 2-Factor Authentication (2FA) | CrowdStrike | SafeBase | documented | - | - |
| 2. Individual rights request | Everbridge | SafeBase | documented | - | - |
| 2.1 Processes and mechanisms for applying secure configurations to all system components are defined and understood. | Staq.io | Vanta Trust Center | documented | - | - |
| 2.1.1 | Xactus | Vanta Trust Center | documented | - | - |
| 2.1.2 | Xactus | Vanta Trust Center | documented | - | - |