---
title: "EFROS Trust Center: Security & Compliance Information"
description: "EFROS Trust Center. Security and compliance overview, certifications, data handling, IR, vendor due diligence. Documentation under NDA."
canonical: https://efros.com/trust/
metadata_source: searchatlas-otto
---

- [Home](https://efros.com/)
- /Trust Center

● TRUST CENTER

# Verifiable evidence. Audited annually.

Security and compliance documentation for executives, insurance reviewers, legal teams, vendor-risk teams, and enterprise buyers. Public statements below. NDA-gated artefacts available on request within five business days.

[Request documentation under NDA](mailto:trust@efros.com) [Run Free Security Score](https://efros.com/free-security-assessment/)

SOC 2 readiness

ISO 27001 SoA

IS Policy

BCDR Plan

IR Playbook

Pentest Summary

Insurance

Sub-processors

NDA · Verified clients only

SOC 2 readiness

ISO 27001 SoA

IS Policy

BCDR Plan

IR Playbook

Pentest Summary

Insurance

Sub-processors

NDA · Verified clients only

● PUBLIC VERIFICATION

## Independently rated. Continuously monitored.

EFROS's external security posture is rated continuously by SecurityScorecard's automated assessment platform. The score below reflects our public-facing infrastructure: DNS, email authentication, TLS, application security, network endpoints, patching cadence, IP reputation, and hacker chatter. No self-reporting. Signals are observed by third parties. Click the badge to view the live public report.

[SecurityScorecard100/100View live report→](https://scores.securityscorecard.io/security-rating/efros.com)

How to interpret this score
- 90-100Grade A: strong external posture. Top decile of organizations rated by SecurityScorecard.
- 80-89Grade B: solid posture. Typical mid-market with an active security program.
- 70-79Grade C: acceptable but with material gaps. Typical organization without a dedicated security program.
- Methodology source: [SecurityScorecard 10 Risk Factors](https://securityscorecard.com/blog/securityscorecard-10-risk-factors-explained). Independent ratings updated continuously by SecurityScorecard. No EFROS self-reporting.

## 1. Security & Compliance Overview

EFROS is a cybersecurity-first managed service provider. Every engagement runs under documented controls aligned to recognised frameworks. Independent attestations and partner-tier letters are reviewed annually and provided under NDA to qualified prospects.

## 2. Certifications & Partner Evidence

EFROS operates against the certifications, partner programs, and frameworks listed below. Supporting evidence (Statement of Applicability, attestation report, partner-tier letter, engineer credentialing) is released under mutual non-disclosure agreement to qualified clients and their insurance, legal, or audit reviewers.
- ISMS aligned to ISO/IEC 27001:2022. Statement of Applicability under NDA
- AICPA SOC 2 Trust Services Criteria. Internal controls mapped. EFROS is not SOC 2 certified and holds no attestation report
- Microsoft Solutions Partner program (tier letter under NDA)
- AWS Technology Partner program (tier letter under NDA)
- Cisco Partner program designation (tier letter under NDA)
- Individual engineer credentialing (CompTIA, vendor-specific). List under NDA

## 3. Documentation Available Under NDA

The following items are released to qualified clients and their insurance, legal, or audit reviewers under mutual non-disclosure agreement.
- ISO 27001 Statement of Applicability (SoA)
- Information Security Policy and supporting standards
- Business Continuity and Disaster Recovery Plan
- Incident Response Playbook (sanitised)
- Third-party penetration test executive summary
- Insurance certificates: cyber, professional indemnity, general liability
- Sub-processor list with data flow diagram

## 4. Data Handling

Client data stays in the client's own tenant by default. EFROS engineers operate with the minimum access required for the engagement. Read-only auditor or global-reader roles are preferred where the task allows. Elevated access is time-boxed, logged, and reviewed.
- Default: data stays in client tenant; EFROS does not retain custody
- Encryption at rest: AES-256 on all EFROS-managed systems
- Encryption in transit: TLS 1.2+ with HSTS and MTA-STS enforcement
- Audit logs: 12-month minimum retention. Longer for regulated scope
- Access reviews: quarterly for all client tenants
- Sub-processor disclosure: complete list under NDA

## 5. Privacy & Confidentiality

EFROS operates against GDPR, UK GDPR, CCPA / CPRA, HIPAA (where BAA in place), and PIPEDA expectations. Every engagement contract includes confidentiality covenants. Employees sign individual confidentiality agreements and complete annual data-handling training.
- Annual data-protection training for every employee
- Background screening for production access
- Multi-factor authentication on every system
- Privileged access management (PAM) with session recording for sensitive systems
- Onboarding and offboarding within 4 business hours under documented runbook

## 6. Incident Response Process

If an incident hits a client environment, the 24×7 SOC contains first, communicates with the client's designated incident contact, and follows the runbook documented at engagement onboarding. Severity classification and SLA targets are the canonical P1-P4 matrix below (Section 6a).
- Designated incident contact named at engagement start, validated quarterly
- Forensic readiness: timeline preservation, memory captures, chain-of-custody
- Regulatory notification timing tracked against jurisdiction (e.g. OCR for HIPAA, NYDFS 23 NYCRR 500 §500.17, GDPR 72-hour clock)
- Post-incident review with root-cause analysis and remediation roadmap

## 6a. Incident Response SLA Matrix

Priority bands and response SLAs for incident response under EFROS Fortress SOC engagements. Lower-tier programs (Core IT, Secure Operations) follow the same bands with business-hours-only coverage on P3 and P4.

| Priority | Definition | Acknowledge | Containment status | Mitigation target | Formal notification |
| --- | --- | --- | --- | --- | --- |
| P1 — Critical | Customer-impacting outage or active confirmed incident | 30 minutes | 1 hour | 4 hours | ≤ 24 hours |
| P2 — High | Degraded service or contained security alert | 1 hour | 4 hours | 1 business day | If regulatory clock applies |
| P3 — Medium | Non-urgent issue or standard change request | 4 business hours | n/a | 3 business days | n/a |
| P4 — Low | Informational, scheduled change or maintenance | 1 business day | n/a | 5 business days | n/a |

Regulatory-notification clocks (HIPAA OCR, NYDFS Part 500 §500.17 72-hour, GDPR/UK GDPR 72-hour, state breach statutes) run in parallel with this matrix and are tracked per-incident against jurisdiction. Performance against this matrix is reported quarterly under NDA via the Trust Center.

## 7. Insurance & Risk Documentation

EFROS carries cyber-liability, professional-indemnity, and commercial-general-liability coverage. Certificates of insurance are provided to qualified prospects under NDA. Carrier-specific attestations are available for clients whose own cyber insurance requires vendor-side documentation (Beazley, Chubb, AIG, Travelers, and the major specialty markets).

## 8. Vendor Due Diligence Contact

For procurement reviewers, security questionnaires (SIG, CAIQ, SAQ, custom), and audit requests, route directly to our compliance team. We return completed questionnaires within five business days.
- Email: trust@efros.com
- Standardised: SIG Core, SIG Lite, CSA CAIQ
- Custom questionnaires: returned with evidence references and policy excerpts
- Audit calls: scheduled within 10 business days, attended by EFROS security lead
- Privacy resources: Privacy Policy (/privacy/), Sub-processors (/privacy/#sub-processors), DPA request (dpa@efros.com)

## 9. Responsible Disclosure

Security researchers reporting vulnerabilities in EFROS-operated systems or client environments under our scope are welcome. We follow a coordinated disclosure model and do not pursue legal action against researchers acting in good faith.
- Contact: security@efros.com
- PGP key and security.txt published at /.well-known/security.txt
- Triage: acknowledged within 2 business days
- Validation window: 7-30 days depending on scope
- Coordinated disclosure window: 90 days by default, adjustable for active exploitation

10. Frequently Asked

## Questions executives ask.

How do I verify EFROS's partner statuses? + Microsoft Solutions Partner status is verifiable via Microsoft Partner Center. AWS Partner status is verifiable via the AWS Partner Network directory. Cisco Partner status (Cisco 360 Partner Program, 2026) via the Cisco Partner Locator. ISO 27001 and SOC 2 attestations are released under NDA.

Will EFROS sign our security questionnaire? + Yes. Standardised questionnaires (SIG, CAIQ) are returned within 5 business days. Custom questionnaires within 10 business days. We sign with evidence references. Never with claims that exceed our actual controls.

Will EFROS sign a Business Associate Agreement (BAA)? + Yes. We sign BAAs with every healthcare client and run HIPAA-aligned controls as a default. The BAA is signed before any PHI-relevant systems are touched.

Where does our data live? + In your tenant. EFROS engineers operate against your Microsoft 365, Google Workspace, AWS, Azure, or Google Cloud tenant under read-only or scoped credentials. EFROS does not retain custody of client data outside the agreed evidence retention window (typically 12 months). Destruction is verifiable.

What happens at the end of an engagement? + All documentation, configuration, and runbooks stay in your tenant. EFROS retains evidence files under encryption for the contractually agreed retention period (default 12 months), then destroys them with verifiable sign-off. You can request earlier destruction at any time.

How are background checks handled? + Every EFROS employee with production access completes a criminal background screening through a reputable vendor before starting. Renewed for sensitive engagements. References available under NDA.

● Visible proof

## What the deliverable actually looks like.

Anonymized samples drawn from real engagements. Every artifact below is a representation of what an EFROS client receives as part of an assessment, incident-response retainer, or managed service. Operational outputs, not marketing slides.

EFROS Passive Assessment · Sample · Anonymized

v1.0 · Letter

Overall security score

86 Grade B out of 100

Posture

Above-average for industry · 3 priority remediations

Domain A

DNSSEC · CAA 89/100

Email Auth B

SPF · DKIM · DMARC 72/100

Web Security A

HSTS · CSP 91/100

Brand A+

Typosquats · BIMI 96/100

Infrastructure A+

DNSBL · CDN 100/100

Compliance C

GDPR · security.txt 65/100

P2 F-007 · Medium CVSS 6.1 · Confirmed

DMARC policy at p=none allows spoofed mail through

Recommended: move to p=quarantine within 14 days after a 30-day aggregate-report review, then to p=reject. Owner: IT lead. Effort: 2 hours.

Page 3 · 14 CONFIDENTIAL · SAMPLE · COPY-A1F2B3

Incident Response · Ransomware · Sample · Anonymized

MTTD / MTTR targets contracted per SLA

3 min

Time to triage (sample)

15 min

Time to client notify (sample)

10 hr

Time to restore (sample)
- T+0Detection· SOC analyst · automatedEDR isolates first compromised endpointDefender for Endpoint blocks file-encryption pattern, isolates host from network. Initial alert fires in SOC console.
- T+3 minDetection· SOC tier-2SOC analyst opens incident, runs scope queryIdentity, lateral-movement, and persistence indicators pulled from SIEM. Two additional endpoints flagged with matching IOCs.
- T+8 minContainment· SOC tier-2 · IR leadContainment: identity + endpoint quarantineCompromised user revoked, sign-in sessions terminated. All three endpoints isolated. Lateral targets pre-emptively isolated.
- T+15 minContainment· IR lead → Client CISO / OwnerClient notification + IR call bridge openedNotification per pre-agreed SLA. Bridge opened with client lead, EFROS IR lead, and SOC on the line. Initial scope and impact statement delivered.
- T+45 minInvestigation· DFIR engineerForensic acquisition + threat-actor identificationMemory image, disk snapshot, and log preservation. TTPs matched against known affiliate. Initial-access vector identified (phished M365 account, no MFA).
- T+4 hrRecovery· Senior engineer + DFIREradication + clean-rebuild starts on isolated VLANConfirmed-clean baseline images deployed to a quarantine VLAN. Patient zero credential rotated, app-password reset across affected services.
- T+10 hrRecovery· Backup engineerRestore from immutable backup, verified cleanThree-2-1 backup restored to clean infrastructure. Hash integrity verified, AV scan clean. User-facing systems back online on a watched VLAN.
- T+48 hrReview· IR lead + ClientPost-incident review + hardening planWritten report delivered: TTPs, IOCs, what worked, what didn't, mandatory hardening (MFA, Conditional Access, log retention). Lessons documented for tabletop.

Real-world sequence from a logistics-sector engagement. Customer details anonymized. EFROS retainer clients receive a written post-incident report with TTPs, IOCs, and a mandatory hardening roadmap within 72 hours of resolution.

Microsoft 365 Hardening · Sample · Anonymized

15 controls · 5 areas

6

Implemented

4

Partial

5

Missing

| Status | Area | Control | Note |
| --- | --- | --- | --- |
| ✓Implemented | Identity· ImplementedMFA enforced for all licensed usersConditional Access policy 'Require MFA for all users' active | | |
| ~Partial | Identity· PartialPrivileged accounts on FIDO2 or Authenticator with number-match3 of 5 Global Admins still on SMS — schedule cutover | | |
| ✓Implemented | Identity· ImplementedConditional Access blocks legacy authenticationPolicy active; 0 legacy-auth sign-ins last 30 days | | |
| ✗Missing | Identity· MissingRisk-based sign-in policy and user-risk policy enabledEntra ID P2 features available but not configured | | |
| ~Partial | Email security· PartialSPF / DKIM / DMARC at p=reject with aggregate reportingDMARC at p=quarantine; ready to move to p=reject in 30 days | | |
| ✓Implemented | Email security· ImplementedAnti-phishing impersonation protection (Defender for Office 365)Mailbox-intelligence on; 4 executives in protected-users list | | |
| ✓Implemented | Email security· ImplementedSafe Links and Safe Attachments policies tunedDynamic delivery on; click-time URL rewriting active | | |
| ✗Missing | Email security· MissingExternal-sender warning banner on inbound mailTransport rule not deployed — recommended for BEC defense | | |
| ✓Implemented | Endpoint· ImplementedDefender for Endpoint or third-party EDR on all devicesDefender P2; 248 of 248 devices reporting | | |
| ~Partial | Endpoint· PartialIntune compliance policy gates Conditional AccessWindows compliant; macOS and iOS compliance policies pending | | |
| ✗Missing | Endpoint· MissingAttack Surface Reduction rules in audit-then-block modeASR rules not enabled — high-leverage hardening | | |
| ✗Missing | Data· MissingSensitivity labels with auto-classification on top 3 categoriesPurview unlicensed or unconfigured | | |
| ~Partial | Data· PartialDLP policies for credit-card / SSN / health dataDLP on email only — extend to Teams, SharePoint, OneDrive | | |
| ✓Implemented | Audit· ImplementedUnified audit log enabled and retention extended to 1 year+Audit log on; retention at default 180 days — extend to 365 | | |
| ✗Missing | Audit· MissingAlert policies routed to SOC or 24×7 monitoringAlerts firing into a shared inbox no one watches at 2 AM | | |

Sample shown. The full M365 posture assessment covers 60+ controls across Identity, Email, Endpoint, Data, Apps, and Audit. Evidence is collected directly from your tenant under a read-only delegated app permission.

Backup & DR Readiness · 3-2-1-1-0 · Sample · Anonymized

10 checks · 1 ransomware test

6

Pass

2

Warn

2

Fail

| Status | Rule | Detail | Evidence |
| --- | --- | --- | --- |
| ✓Pass | 3 copies of every protected workload· PassProduction + on-prem repo + cloud repo for tier-1 systemsEvidence: Veeam job report: 100% of tier-1 systems with 3 copies | | |
| ✓Pass | 2 different storage media· PassDisk-based repo + object-storage cloud tierEvidence: Wasabi S3 immutable tier + local ReFS volume | | |
| ✓Pass | 1 copy off-site, geographically separated· PassCloud copy in a region >300 km from primary siteEvidence: Cloud copy in EU-Central, primary in EU-West | | |
|!Warn | 1 copy immutable (object-lock or air-gap)· WarnHardened repository or S3 Object Lock with retention periodEvidence: Object Lock at 14 days — recommended minimum is 30 days | | |
| ✗Fail | 0 backup verification errors· FailSureBackup or recovery-verification job passes on every restore pointEvidence: 4 of 12 tier-1 jobs without verification configured | | |
|!Warn | Quarterly full-restore test, written record· WarnA complete restore-to-clean-infrastructure dry-run with documented timingEvidence: Last test 11 months ago — overdue per policy | | |
| ✓Pass | RTO target documented per workload tier· PassRecovery Time Objective per system, agreed with the businessEvidence: Tier-1: 4 hr · Tier-2: 24 hr · Tier-3: 72 hr (signed off) | | |
| ✓Pass | RPO target documented per workload tier· PassRecovery Point Objective expressed in minutes/hours of data lossEvidence: Tier-1: 15 min · Tier-2: 4 hr · Tier-3: 24 hr | | |
| ✗Fail | Backup credentials separated from production AD· FailA compromised domain admin must not be able to delete backupsEvidence: Veeam service account is a domain admin — high-risk finding | | |
| ✓Pass | Backup repository monitored by SOC· PassAlerts route to a 24×7 watched queue, not a shared inboxEvidence: Veeam ONE → Wazuh → SOC ticketing pipeline live | | |

Modeled on Veeam's 3-2-1-1-0 rule. The full backup-readiness assessment includes a live quarterly restore-test exercise, RTO/RPO validation per workload, and immutable-repo configuration review.

## Request documentation.

For vendor-risk reviewers, audit teams, or enterprise procurement. Stefan responds personally within 1 business day with the NDA and the requested artifact.

Your name *

Company *

Work email *

Role (optional)

Document requested * SOC 2 Trust Services Criteria readiness documentation ISO/IEC 27001 alignment documentation (Statement of Applicability) CAIQ — Consensus Assessments Initiative Questionnaire SIG Lite questionnaire SIG Core questionnaire HECVAT (higher-ed) Partner-tier attestation letter (Microsoft, Cisco, AWS, etc.) Data Processing Agreement (DPA) Incident response plan summary Penetration test summary Cyber insurance certificate Sub-processor list Other — describe in context field

Context (optional)

Request documentation Stefan responds personally within 1 business day with the NDA + the requested artifact. No marketing follow-up.

Prefer email? [trust@efros.com](mailto:trust@efros.com)

Related

## For procurement and audit teams

[### Partners & Certifications ISO 27001, SOC 2, vendor partner-tier letters, and the frameworks EFROS operates against.Open→](https://efros.com/partners/) [### Vendor Risk Questionnaire The 60-question template. What we ask our own vendors, and what we answer for yours.Open→](https://efros.com/resources/vendor-risk-questionnaire/) [### SOC 2 Readiness What the AICPA Trust Services Criteria look like in evidence form.Open→](https://efros.com/resources/soc-2-readiness-checklist/) [### Team The named individuals on the engagement and the credentials they hold.Open→](https://efros.com/team/) [### How We Engage The engagement model, SLAs, and what to expect through onboarding.Open→](https://efros.com/how-we-engage/) [### Privacy Policy Data handling, sub-processors, and regional jurisdiction details.Open→](https://efros.com/privacy/)
