VENDOR DUE DILIGENCE

Security is not a project, it's a discipline.

Built for business-critical workflows. Independently verified to ensure your sensitive capital markets data stays protected.

INDEPENDENTLY VERIFIED

Take a look at our certs and attestations.

Certification

ISO/IEC 27001 Certified

Polly has been certified for multiple consecutive years against the international standard for InfoSec management systems.

ISO 27001 means our approach to protecting customer data has been independently audited against a rigorous global standard. It covers how we manage access controls, assess and treat risk, respond to incidents, and continuously improve our security posture.

ISO/IEC 27001 Certificate available upon request.
Attestation

SOC 2 Type II Attestation

Independently examined by a licensed CPA firm against the AICPA Trust Services Criteria.

Where ISO 27001 certifies that we run a sound security management system, the SOC 2 reports on whether our specific controls were designed appropriately and operate effectively. A Type II report covers control performance across an observation period rather than a single point in time, so it reflects how we actually operate day to day.

The full report is available under NDA.
HOW WE OPERATE

Controls and safeguards:

Data protection and encryption

Polly is ISO/IEC 27001 certified and SOC 2 Type II attested, and built for institutions that answer to regulators. Data is classified and protected accordingly, with encryption applied to the standards our customers expect. Engineers have no standing access to production data; emergency access is tightly scoped, authorized, and logged. Production systems are hardened to run only what is required and monitored continuously for suspicious activity, file integrity, vulnerabilities, and malware. Security isn't a feature of our platform; it's a precondition for it.

Access control and identity management

Access to Polly systems is granted on a minimum-necessary basis and limited to what a role actually requires, for employees, contractors, consultants, and third-party providers alike. Every identity is named, every entitlement is tied to a role, and access is removed when it's no longer needed. Anyone with access to our systems is responsible for reporting suspected unauthorized use immediately.

Vulnerability management

Polly's production systems are scanned for vulnerabilities on a regular cadence, and results from both automated scanning and penetration testing are reviewed by our Security team to separate real risk from noise. Confirmed vulnerabilities are tracked through a formal remediation process. Each one is resolved, granted an approved exception, or subject to documented risk acceptance. Nothing gets closed by being ignored.