SOC2C

Is this your company? Buyers are checking Magnus Health here. Claim magnushealth.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Magnus Health logo

Magnus Health

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Magnus Health is SOC 2 Type II compliant. Magnus Health also holds HIPAA, and CCPA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Trust Magnus Health (part of the Veracross group) to take care of your security and privacy. Our Trust Center links you to all our privacy, security, and compliance programs, giving you all the info to manage your data confidently. Want access to our AI-enabled Trust Center? Request access now ↗️ [Product Privacy Policy](https://magnushealth.com/product-privacy-policy/) [Website Privacy Policy](https://magnushealth.com/website-privacy-policy/) [DSAR](https://privacy.saymine.io/veracross?type=donotsell) [Customer Data Processing Agreement (DPA)](https://vcwebdistro.blob.core.windows.net/web/All

Compliance & infrastructure

Hosting
AWS

Documents

3

Subprocessors

18
  • 1
    1Password · Password Management
    US
  • A
    Atlassian · Support tickets & documentation
    United States
  • A
    Amazon Web Services · IaaS, hosting, databases, file storage, CDN
    United States
  • D
    DocuSign · Document management
    United States
  • M
    Microsoft 365 · Email processing & delivery, file storage
    United States
  • P
    Pardot · Customer relationship management
    United States
  • S
    Salesforce · Customer account management
    United States
  • S
    Slack · Business communications
    United States
  • S
    StoredTech · Managed Service Provider
    United States
  • Z
    Zoom · Video calls, conferences, webinars
    United States
  • P
    Postmark App · Telecommunication
    United States
  • V
    Vanta · Continuous security and compliance monitoring
    United States
Show all 18 subprocessors
  • M
    MineOS · Vendor & privacy management
    United States, Israel
  • W
    WordPress · Landing & product pages
    United States
  • W
    Workable · Recruiting, candidate management
    United States
  • M
    Mimecast · Email security
    United States
  • L
    Litmos · Learning & training management
    United States
  • R
    Recorded Future · Security Operations
    United States

Compliance leadership

The person who leads Magnus Health's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Magnus Health's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Magnus Health SOC 2 compliant?
Magnus Health is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Magnus Health HIPAA compliant?
According to Magnus Health's public trust center, Magnus Health is HIPAA compliant. On SOC2C this listing is Listed.
Is Magnus Health CCPA compliant?
According to Magnus Health's public trust center, Magnus Health is CCPA compliant. On SOC2C this listing is Listed.
Is Magnus Health SOC 2 Type I or Type II?
Magnus Health is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Magnus Health's SOC 2 for a vendor risk assessment?
Yes. Magnus Health's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by Magnus Health

Reproduced from Magnus Health's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How does Magnus Health protect customer data?
Please see Magnus Health's Controls for details on what we do to protect customer data.
How does Magnus Health protect itself from bad actors on the dark web?
Magnus Health employs advanced monitoring of the dark web using a tool called Recorded Future which automatically scans and collects data from dark web sources. This information is used to identify potential threats, such as leaked credentials or sensitive company information. When compromised credentials are detected, these high priority alerts are automatically routed to our internal IT team who then take the necessary steps to mitigate the risk. With the ability of Recorded Future to proactively detect potential threats, it allows us to take preventative measures like password resets or account lockouts before a bad actor can utilize these credentials in a malicious manner. By staying vigilant and proactive, Magnus Health is actively mitigating the risk of unauthorized access and potential data breaches, ensuring a higher level of security.
Does Magnus Health encrypt data?
Customer data is protected by TLS 1.2+ encryption when in-flight and AES-256 encryption when at rest.
Does Magnus Health have an incident response plan?
Magnus Health maintains an incident response team (IRT) made up of technical, and management personnel. The incident response plan follows several high-level phases including: - Event assessment - Breach assessment & containment - Reporting - Post-breach activities
Does Magnus Health monitor for intrusions on a 24x7x365 basis?
Magnus Health utilizes a dedicated Security Operations Center (SOC) to monitor 24x7x365. Additionally, Magnus Health has the following security measures in place: - Web Application Firewalls - Distributed Denial of Service (DDoS) mitigation - File Integrity Monitoring (FIM) - Intrusion Detection System (IDS)