Control Mapping Matrix (CSV)
Framework domain to control coverage mapping used in procurement reviews.
v2026.03.04.1 • Updated 2026-03-04 • Verified against code/deploy posture
DownloadTrust Center
Hercules applies tenant isolation, strict validation, protected auth flows, and request-scoped auditability. The matrix below maps active controls to major framework domains.
Last updated: 2026-03-21
| Control Domain | Framework Mapping | Code/Operational Evidence |
|---|---|---|
| Access Control | ISO 27001 A.5.15, SOC 2 CC6 | RS256 auth, role checks, tenant-scoped authorization middleware |
| Tenant Segregation | ISO 27001 A.8.2, SOC 2 CC7, CBN Risk-Based Cybersecurity Framework | PostgreSQL RLS with tenant context enforced on every query |
| Secure Development | ISO 27001 A.8.28, SOC 2 CC8 | TypeScript strict mode, Zod validation, CI lint/type/test gates |
| Monitoring and Logging | ISO 27001 A.8.15, SOC 2 CC7 | Structured request-scoped logs, audit log with operator attribution, 90-day retention |
| Resilience and Continuity | ISO 27001 A.5.30, SOC 2 A1, CBN BCM expectations | Health/readiness checks, managed database and Redis services, graceful shutdown |
| Data Minimisation and Lawful Basis | NDPR Art. 2.1-2.3, NDPA 2023 Ch. 3 | Names, work emails, and interaction events only. Lawful basis: legitimate interest for security awareness training. |
| Data Subject Rights | NDPR Art. 2.6, NDPA 2023 Ch. 4 | Rights requests acknowledged within 72 hours and coordinated with tenant-controller as data controller |
| Cross-Border Transfer Safeguards | NDPR Art. 2.11, NDPA 2023 Ch. 7 | Contractual DPA safeguards; Railway infrastructure disclosed; tenant-controllers advised on CBN residency obligations |
Control Mapping Matrix (CSV)
Framework domain to control coverage mapping used in procurement reviews.
v2026.03.04.1 • Updated 2026-03-04 • Verified against code/deploy posture
DownloadSecurity Contact SLA (TXT)
Response-time commitments for customer-reported security issues.
v2026.03.04.1 • Updated 2026-03-04 • Verified against code/deploy posture
DownloadIncident Response Summary (TXT)
Notification and escalation summary aligned to current operational process.
v2026.03.04.1 • Updated 2026-03-04 • Verified against code/deploy posture
Download