Compliance
KeyCare Pass and SOC 2
If your company is preparing for a SOC 2 examination, KeyCare Pass can support controls in the logical access and monitoring parts of the Trust Services Criteria.
Prices and options by email
How to get started today
KeyCare Pass is not certified against this framework, and GovPAM does not claim that using it makes an organization compliant. This page describes how KeyCare Pass's features can support your own compliance work. It is not legal or audit advice.
What SOC 2 asks for
SOC 2 reports, issued by an independent auditor under the AICPA's attestation standards, evaluate a service organization's controls against the Trust Services Criteria for security, availability, processing integrity, confidentiality and privacy.
The report is about your organization's system and controls. KeyCare Pass does not have a SOC 2 report of its own.
Where KeyCare Pass fits
Common Criteria where a password manager can be part of your controls.
| What is asked for | How KeyCare Pass can help | Plans |
|---|---|---|
| CC6.1 Logical access security | Vault data is encrypted on each person's device (AES-256 with HMAC-SHA256); keys come from the master password through PBKDF2-SHA256 or Argon2id; traffic uses TLS. Two-step login is available on every account. | All plans; required by policy on Enterprise |
| CC6.2 Registering and removing users | Invite and confirm members, revoke access to suspend them, and remove them when they leave. | Teams, Enterprise |
| CC6.3 Role-based access and least privilege | Collection permissions from view-only to manage, groups and custom roles. | Custom roles on Enterprise |
| CC7.2 Monitoring for anomalies | Event logs with IP addresses, sign-in activity and alerts about sign-ins from new addresses. | Teams, Enterprise |
What stays with you
A password manager is one control among many. These remain your organization's work:
- Defining your controls and gathering evidence for the auditor
- Vendor management, including GovPAM as a vendor
- Access reviews on a schedule your auditor accepts
- Retaining logs for as long as your controls require
Frequently asked questions
Can you give us your SOC 2 report?
KeyCare Pass does not have a SOC 2 report. We can describe its design, hosting and data handling for your vendor review.
Will event logs satisfy our auditor?
They are useful evidence of access and changes. Whether they are sufficient depends on your controls and your auditor.
Need details for your auditor?
Ask us about KeyCare Pass's design, hosting and data handling.