Vulnerability management, security policies, and the current CVE report.
TopQuadrant maintains SOC 2 Type 2 compliance.
Area Policy
Open source software
TopQuadrant maintains a current list of the open source software used in EDG. The libraries are updated regularly so that current security patches are applied.
Scans
The TopQuadrant code base is monitored continually for known vulnerabilities. A complete scan is run before every release. Contact TopQuadrant support for a copy of the report.
Response
Every vulnerability is analysed for impact and severity. A vulnerability that is critical in normal operation of the software is remedied with a patch, a new release, or mitigation controls. Non-critical vulnerabilities are remedied in the following release.
Notification
Customers are notified through TopQuadrant support when a critical vulnerability is found that affects the software and its use.
Reporting
To report a security concern or ask a question about TopQuadrant software, contact security@topquadrant.com.
The CVEs addressed in the latest release, with historical data. Further detail is in the