Built for business-critical workflows. Independently verified to ensure your sensitive capital markets data stays protected.
Polly has been certified for multiple consecutive years against the international standard for InfoSec management systems.
ISO 27001 means our approach to protecting customer data has been independently audited against a rigorous global standard. It covers how we manage access controls, assess and treat risk, respond to incidents, and continuously improve our security posture.
Independently examined by a licensed CPA firm against the AICPA Trust Services Criteria.
Where ISO 27001 certifies that we run a sound security management system, the SOC 2 reports on whether our specific controls were designed appropriately and operate effectively. A Type II report covers control performance across an observation period rather than a single point in time, so it reflects how we actually operate day to day.
Polly is ISO/IEC 27001 certified and SOC 2 Type II attested, and built for institutions that answer to regulators. Data is classified and protected accordingly, with encryption applied to the standards our customers expect. Engineers have no standing access to production data; emergency access is tightly scoped, authorized, and logged. Production systems are hardened to run only what is required and monitored continuously for suspicious activity, file integrity, vulnerabilities, and malware. Security isn't a feature of our platform; it's a precondition for it.
Access to Polly systems is granted on a minimum-necessary basis and limited to what a role actually requires, for employees, contractors, consultants, and third-party providers alike. Every identity is named, every entitlement is tied to a role, and access is removed when it's no longer needed. Anyone with access to our systems is responsible for reporting suspected unauthorized use immediately.
Polly's production systems are scanned for vulnerabilities on a regular cadence, and results from both automated scanning and penetration testing are reviewed by our Security team to separate real risk from noise. Confirmed vulnerabilities are tracked through a formal remediation process. Each one is resolved, granted an approved exception, or subject to documented risk acceptance. Nothing gets closed by being ignored.