Compliance Program
DuoCircle's compliance program is anchored by a SOC 2 Type II examination performed annually since 2022 by Hancock Askew and Co, LLP, covering all four Trust Services Criteria. DuoCircle also maintains CSA STAR Level 1 self-assessments for six services in the public Cloud Security Alliance registry and a current HECVAT Full for higher education, and answers other frameworks from that existing SOC 2 evidence rather than maintaining duplicate attestations. Reviewed 2026-05-06.
Frameworks at a glance
Where we have a current attestation, we say so. We do not claim certifications we do not hold. If our completed responses reference a framework not on this list, they map back to the SOC 2 evidence we already maintain.
| Framework | Standard | Status | Access |
|---|---|---|---|
| SOC 2 Type II | AICPA SSAE 18 / TSP section 100A | Examined annually since 2022 | Under Bonterms Mutual NDA |
| CSA STAR Level 1 | CAIQ Lite, subset of CCM v4.1 | Six services in the public registry | Public, no NDA |
| HECVAT Full | EDUCAUSE Higher Education Community Vendor Assessment Toolkit | Current version | Under Bonterms Mutual NDA |
CSA STAR Level 1
The Cloud Security Alliance Security, Trust, Assurance, and Risk (STAR) Registry is the public, no-NDA way to review our compliance posture. The Level 1 self-assessment is a CAIQ Lite questionnaire mapped to a subset of the CCM v4.1 control framework. It is the right place to start early-stage diligence.
View on cloudsecurityalliance.orgSOC 2 Type II
Examined annually by Hancock Askew & Co, LLP since 2022. The report covers Security, Availability, Confidentiality, and Processing Integrity. Available to customers and serious prospects under the Bonterms Mutual NDA, which we publish in advance so your legal team can review it before any conversation begins.
Request the SOC 2 reportHECVAT, for colleges and universities
The Higher Education Community Vendor Assessment Toolkit (HECVAT) is the standardized security questionnaire used by colleges and universities to evaluate cloud vendors. We maintain a current HECVAT Full and share it with higher-ed prospects under the same Bonterms Mutual NDA we use for SOC 2. If you need the HECVAT Lite or a specific section answered for a single product, tell us in the request and we will tailor what we send.
Per-product compliance pages
Each product publishes its own /compliance page with the CSA STAR registry entry, supported standards, and any product-specific evidence. Use these for product-scoped procurement reviews.
- AutoSPF SPF flattening and management
- DMARC Report DMARC RUA aggregation and reporting
- Phishing Protection Inbound phishing and malware filtering
- Outbound SMTP Transactional and bulk SMTP relay
- Tenant Migration Microsoft 365 tenant-to-tenant migration
- Alumni Forwarding Lifetime email forwarding for alumni programs
- Mail Flow Monitoring Synthetic delivery probes and uptime
- NuReply Cold email outreach service
- InboxIssue Email deliverability testing
What we do not currently offer
We say what we are. We also say what we are not. If a regulatory regime requires a posture we do not hold, that is the most useful thing we can tell you up front.
- HIPAA Business Associate, not by default. If your use case requires a Business Associate Agreement, contact us before deployment.
- FedRAMP authorization, not held. We do not currently offer FedRAMP-authorized cloud services.
- PCI DSS Level 1 in mail bodies, not supported. Cardholder data must not be transmitted in mail bodies through services not specifically provisioned for that data class.
- ISO 27001 standalone certification, not held. SOC 2 covers an overlapping control set, and our completed responses map ISO-referenced questions back to our existing evidence.
Need a framework we did not list?
Most security questionnaires map to controls we already document. We share our completed responses with prospects before signing, and complete your own custom questionnaire once you are a customer under contract.
Request documents