What Clients Can Request
Dev Technosys might not presently have a SOC 2 report, but clients may communicate
their exact needs related to security and compliance directly with the organization
in the procurement process.
Depending on the specific engagement, organizations may ask for information regarding
the security policies, access control, confidentiality procedures, secure software
development, incident management, data processing, and business continuity systems,
among others.
In addition, clients who have formal compliance obligations should also inform the
organization regarding them before entering into the development agreement. This
enables both parties to know what contractual, technical, and organizational
measures can be applicable to the engagement.