SOC2C

Is this your company? Buyers are checking Dynamify here. Claim dynamify.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Dynamify logo

Dynamify

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Dynamify is SOC 2 compliant. Dynamify also holds GDPR, and PCI DSS.

Framework
SOC 2
Auditor
Last report
Renewal
View official trust center ↗

About

Dynamify is the #1 omnichannel platform for the contract catering industry, processing almost $350m in annual transactions in over 3,000 restaurants in 20 countries With security and data protection at our core, Dynamify has created this centralized resource where you can find the latest information about our data security practices, protocols, and compliance

Compliance & infrastructure

Hosting
AWS
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

41
POLICIES

Subprocessors

3
  • A
    Amazon Web Services · aws
  • G
    Google Workspace · gsuiteadmin
  • V
    Vanta

Compliance leadership

The person who leads Dynamify's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Dynamify's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Dynamify SOC 2 compliant?
Dynamify is SOC 2 compliant. On SOC2C this listing is Listed.
Is Dynamify GDPR compliant?
According to Dynamify's public trust center, Dynamify is GDPR compliant. On SOC2C this listing is Listed.
Is Dynamify PCI DSS compliant?
According to Dynamify's public trust center, Dynamify is PCI DSS compliant. On SOC2C this listing is Listed.
Can I use Dynamify's SOC 2 for a vendor risk assessment?
Yes. Dynamify's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Dynamify penetration tested?
Dynamify hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by Dynamify

Reproduced from Dynamify's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Do you encrypt data at rest and in transit?
Data at Rest. All datastores with customer data, in addition to S3 buckets, are encrypted at rest. Sensitive collections and tables also use column-level encryption. This means the data is encrypted even before it hits the database so that neither physical access, nor logical access to the database, is enough to read the most sensitive information. Data in Transit. Dynamify uses TLS 1.3 everywhere data is transmitted over potentially insecure networks. We also use features such as HSTS (HTTP Strict Transport Security) to maximize the security of our data in transit. Server TLS keys and certificates are managed by AWS and deployed via Application Load Balancers. Secret Management. Encryption keys are managed via AWS Key Management System (KMS). KMS stores key material in Hardware Security Modules (HSMs), which prevents direct access by any individuals, including employees of Amazon and Dynamify. The keys stored in HSMs are used for encryption and decryption via Amazon’s KMS APIs. Application secrets are encrypted and stored securely via AWS Secrets Manager and Parameter Store, and access to these values is strictly limited.
Do you regularly conduct security testing?
Vulnerability Scanning. Dynamify requires vulnerability scanning at least monthly and also at key stages of our Secure Development Lifecycle (SDLC): - Static analysis (SAST) testing of code during pull requests and on an ongoing basis - Malicious dependency scanning to prevent the introduction of malware into our software supply chain - Network vulnerability scanning on a period basis - Software composition analysis (SCA) to identify known vulnerabilities in our software supply chain - Dynamic analysis (DAST) of running applications - External attack surface management (EASM) continuously running to discover new external-facing assets Penetration Testing. Dynamify engages with a different penetration testing consulting firm at least annually. All areas of the Dynamify product and cloud infrastructure are in-scope for these assessments, and source code is fully available to the testers in order to maximize the effectiveness and coverage. Remediation. Security gaps and known weaknesses (e.g. baseline configuration changes, missing patches, end-of-life-status, invalid registry, etc.) are tracked, prioritised according to severity (determined by the rating provided by the National Institute of Standards and Technology (NIST) Common Vulnerability Scoring System (CVSS)), and remediated on a timely basis.
Do you process sensitive cardholder data?
Dynamify does not store, process and/or transmit cardholder data Dynamify develops and maintains merchant-branded applications that integrate with third-party PCI-validated Level 1 payment service providers (PSP). This encompasses card-not-present (using a PSP-hosted iframe) and card-present (using P2PE card machines); tokenization is used in all cases and HSTS is used to enforce HTTPS on API calls. Card brands accepted include American Express, Visa, Mastercard, Discover, and JCB Dynamify is a Level 1 PCI Service Provider
Has your company previously experienced a security incident?
No Security is core at Dynamify and we will continue to make every effort to avoid experiencing a security incident. If a security incident were to arise in the future, Dynamify's incident response team will follow their regular training in implementing an iterative response process designed to investigate, contain exploitation, eradicate the threat, recover system and services, remediate vulnerabilities, and document a post-mortem report including the lessons learned from the incident.
Do you support Single Sign-On (SSO)?
Yes! Single Sign-On (SSO) removes the friction associated with accessing applications powered by Dynamify. Instead of having to create an account with a new username and password, front- and/or back-of-house users simply and securely log in using their institution’s credentials. Multi-factor authentication (MFA) can be enabled as part of SSO. Once logged in, users are authenticated until the sooner of self-performed sign-out or mandatory re-authentication at a frequency specified by the SSO client (e.g. every 90 days) In addition to being more convenient, SSO is more secure: reducing the need to remember passwords (which helps eliminate weak password use) and therefore minimising attack surfaces Dynamify has extensive experience implementing SSO, including with highly-regulated global publicly-listed companies, and supports all major protocols and providers For more information, refer to the Single Sign On (“SSO”) Integration Guide within the Documents section of Dynamify's Trust Report page

Business & Industrial peers that completed SOC 2