SOC2C

Is this your company? Buyers are checking Pendula Solutions Pty Ltd here. Claim pendula.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Pendula Solutions Pty Ltd logo

Pendula Solutions Pty Ltd

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Pendula Solutions Pty Ltd is SOC 2 Type II compliant. Pendula Solutions Pty Ltd also holds ISO 27001, and HIPAA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Pendula is a Customer Engagement Platform that combines a powerful no-code workflow studio. Layered with living and historical customer data, on the spot market and competitive insights, as well as real-time sentiment analysis - Pendula allows businesses to build unsurpassed 1-1 experiences with their customers at scale, building lifelong loyalty and unprecedented Customer Lifetime Value. Pendula was founded in 2016 and is headquartered in Sydney Pendula organisation operates from AWS regions in the US, UK and Australia with all customer data staying in the AWS environment in the selected regi

Compliance & infrastructure

Hosting
AWS

Subprocessors

11
  • A
    Auth0 · Authentication to Pendula platform
    AU, UK or US based on customer choice
  • A
    Amazon Web Services · Cloud hosting all compute and storage infrastructure.
    AU, UK or US based on customer choice
  • G
    GitHub · Source code management
    N/A
  • D
    Datadog · Log management and storage
    US
  • P
    Pulumi · Infrastructure as Code
    N/A
  • P
    PagerDuty · Cloud monitoring and response
  • O
    Okta · All Authentication not directly used by customers.
    US
  • S
    Snyk · Vulnerability Scanning
    N/A
  • T
    Teleport · Privileged Access Management
    SIngapore
  • T
    Twilio · Messaging Services
    Various (depends on SMS destination)
  • O
    OpenAI - Customer · Engineering
    US

Compliance leadership

The person who leads Pendula Solutions Pty Ltd's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Pendula Solutions Pty Ltd's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

FAQ Added and Security White Paper uploadedJan 2025

Pendula has added more documentation on its security included a white paper summary of its environment and an FAQ based on some of the questions from Pendula's entry on the CSA CAIQ

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Pendula Solutions Pty Ltd SOC 2 compliant?
Pendula Solutions Pty Ltd is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Pendula Solutions Pty Ltd ISO 27001 certified?
According to Pendula Solutions Pty Ltd's public trust center, Pendula Solutions Pty Ltd is ISO 27001 certified. On SOC2C this listing is Listed.
Is Pendula Solutions Pty Ltd HIPAA compliant?
According to Pendula Solutions Pty Ltd's public trust center, Pendula Solutions Pty Ltd is HIPAA compliant. On SOC2C this listing is Listed.
Is Pendula Solutions Pty Ltd SOC 2 Type I or Type II?
Pendula Solutions Pty Ltd is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Pendula Solutions Pty Ltd's SOC 2 for a vendor risk assessment?
Yes. Pendula Solutions Pty Ltd's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by Pendula Solutions Pty Ltd

Reproduced from Pendula Solutions Pty Ltd's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How are Pendula's FAQ's organised and what is the source of the questions.
Pendula's FAQs are drawn from questions that are commonly asked from questions, questions from the CSA CAIQ and from the controls implementation guidance for ISO 27001. The grouping of the questions aligns with the ISO 27002:2013. There is one section "Pendula Platform Security Features" which describes Pendula specific security features and architecture.
Are there any material claims or judgements against the company?
No
Has the company suffered Data Loss or Security Breach within the last 3 years
No
Are information governance program policies and procedures sponsored by Pendula’s leadership established, documented, approved, communicated, applied, evaluated, and maintained? Are the policies and procedures reviewed and updated at least annually?
Pendula's senior management team forms Pendula Information Security Management System (ISMS) Governance Council (GC). The ISMS-GC is responsible for establishing, approving and communicating Pendula's information security policies. Pendula's information security policies are reviewed and published whenever major changes occur or on annual basis. All Pendula team members are expected to review all relevant policies on an annual basis.
Does Pendula have an established formal, documented, and leadership-sponsored enterprise risk management (ERM) program that includes policies and procedures for identification, evaluation, ownership, treatment, and acceptance of cloud security and privacy risks?
Pendula's Enterprise Risk Management (ERM) is described in its ISMS policy documents and its risk register is maintained in Vanta. The risks are all reviewed as part of Pendula's ISMS-GC reviews.

Business & Industrial peers that completed SOC 2