SOC 2 program

Controls and evidence tracked against SOC 2 criteria; independent audit is the next milestone

HIPAA

Engagements delivered under signed Business Associate Agreements

Screened

Employees and contractors are screened before client-system access

Quarterly

Security attestations signed by every team member, with recurring security training through the year

Insured

Technology E&O, cyber, commercial crime, and general liability coverage in force

Security starts with who touches your data.

Employees and contractors are screened before being granted access to client systems or data. The standard background check covers criminal records across five years of residence history, with international checks where a team member has lived abroad, and terrorist watchlist screening.

Every team member completes a defined security-awareness onboarding path before access is granted, then recurring training modules and simulated phishing exercises through the year on the KnowBe4 platform. HIPAA training is required before any access to protected health information, and FERPA training before any access to student education records.

Each team member signs a quarterly security attestation covering endpoint detection and response on every work computer, operating system currency, disk encryption, multi-factor authentication wherever available, unique passwords in a managed password vault, VPN use on untrusted networks, credential handling, and phishing vigilance.

Every employment and contractor agreement carries confidentiality, data-handling, and intellectual property obligations that survive the engagement, plus return-of-property requirements on exit.

Secure by architecture, on every engagement

Access and ownership. Access to client systems is limited to assigned project personnel, managed through restricted credential storage, reviewed quarterly, and removed when the assignment ends. Repositories, documentation, and project assets are handed over to client ownership at completion, and any continuing Watkyn access requires the client’s explicit authorization.

We’ve worked under the rules you answer to.

We’ve built and operated systems governed by HIPAA under signed Business Associate Agreements, including COVID-19 case management and vaccination tracking for Saint Louis University. Team members complete HIPAA training before any access to protected health information, and on those engagements we require Business Associate Agreements of our subcontractors before access is granted, preserving the full chain of responsibility the law is designed to create.

Our higher education work is delivered under FERPA’s school-official framework: team members complete FERPA training before any access to student education records, education records are never used to train AI models, and we are prepared to sign an institution’s own FERPA addendum where required.

From public-records obligations to state data privacy law to program reporting rules, each engagement’s regulatory environment is a requirements source from day one, documented in discovery and carried through the security design.

The coverage behind the commitments

Watkyn carries the insurance program an institutional engagement calls for. Current coverage includes technology errors & omissions ($1,000,000 per claim), cyber liability spanning breach response, forensics, notification, regulatory proceedings, cyber extortion, business interruption, and data recovery ($2,000,000), commercial crime including employee theft of client property ($1,000,000), and commercial general liability ($2,000,000 per occurrence / $4,000,000 aggregate).

Certificates of insurance are available on request and govern all terms, limits, exclusions, and endorsements.

One standard, all the way down

Subcontractors sign the same confidentiality and data-handling obligations as employees, pass the same screening, and complete the same security attestations. Where an engagement involves protected health information, subcontractors execute Business Associate Agreements before any access is granted.

The platforms we use in client delivery are reviewed under our vendor risk management process before use and at least annually, and maintained in a vendor inventory. New tools that would process client data require approval before they enter a client environment. Under our standard Data Processing Addendum, the sub-processors supporting an engagement are disclosed to the client, with notice before material changes.

Documents available to evaluators

Common questions about our security program

Is Watkyn SOC 2 certified?

Not yet. Our security program is built and operated against SOC 2 criteria, with controls and evidence tracked continuously, and an independent audit is the next milestone. This page states our exact status and is updated as milestones land.

Can Watkyn sign a Business Associate Agreement?

Yes. We have delivered HIPAA-governed systems under signed BAAs, our team members complete HIPAA training before any access to protected health information, and we require BAAs of subcontractors on those engagements.

Who has access to our data during an engagement?

Only team members assigned to your project, under least-privilege access, screening, signed confidentiality obligations, and quarterly security attestations. Access is removed when the engagement or the assignment ends.

Do you use AI tools when working on our systems?

Yes, under written rules. Our developers use approved AI tools to plan builds and accelerate delivery, and an expert designs, reviews, and stands behind every system we deliver. We do not use client data to train AI models, and we use AI tools and settings designed to prevent submitted client data from being used for model training. Regulated data is gated harder: no protected health information, education records, government-issued identifiers, or financial account data enters any AI tool unless the statement of work authorizes it, the client approves in writing, and the tool is covered by the appropriate data-protection instrument.

Will you complete our security questionnaire or vendor review?

Yes. We respond to questionnaires, vendor reviews, and RFP security sections in your required format, and can provide our written policies under NDA.

What happens if there is a security incident?

Our Incident Response Policy governs the sequence: we investigate promptly, contain the issue, preserve evidence, notify affected clients according to contractual and legal obligations, coordinate with counsel and insurers where appropriate, and document corrective action. Under our standard Data Processing Addendum we notify affected clients without undue delay after becoming aware of an incident, and notification commitments are set per engagement to match your requirements.

Do we need GovCloud or a specialized compliance environment?

Sometimes. When your data or your regulator requires it, we build for it. When it is unnecessary, we say so, because oversized infrastructure wastes public money. The answer comes out of discovery, documented and justified.

Put our security program in front of your evaluators.

Send us your questionnaire, vendor-review packet, or RFP security section. We’ll respond in your format, with evidence.

Questions, or something specific you’re weighing? We’re happy to talk: 201-644-5251.