Security

Vulnerability management, security policies, and the current CVE report.

Vulnerability management and security policies

TopQuadrant maintains SOC 2 Type 2 compliance.

Area Policy

Open source software

TopQuadrant maintains a current list of the open source software used in EDG. The libraries are updated regularly so that current security patches are applied.

Scans

The TopQuadrant code base is monitored continually for known vulnerabilities. A complete scan is run before every release. Contact TopQuadrant support for a copy of the report.

Response

Every vulnerability is analysed for impact and severity. A vulnerability that is critical in normal operation of the software is remedied with a patch, a new release, or mitigation controls. Non-critical vulnerabilities are remedied in the following release.

Notification

Customers are notified through TopQuadrant support when a critical vulnerability is found that affects the software and its use.

Reporting

To report a security concern or ask a question about TopQuadrant software, contact security@topquadrant.com.

Vulnerability report

The CVEs addressed in the latest release, with historical data. Further detail is in the