Frequently Asked Questions
SOC 2 Type II Compliance & Certification Details
What does it mean that Ordr is SOC 2 Type II certified?
Ordr's SOC 2 Type II certification means that an independent, PCAOB-registered third-party auditor has verified Ordr's security controls for Security, Availability, and Confidentiality Trust Service Criteria operated effectively over a continuous 12-month period. This certification demonstrates ongoing commitment to maintaining strong security, availability, and confidentiality standards. Note: SOC 2 Type II certification covers only the specified Trust Service Criteria and requires annual recertification to maintain compliance.
How often does Ordr undergo SOC 2 Type II audits?
Ordr undergoes annual SOC 2 Type II audits to maintain its certification. Each audit covers a continuous 12-month period, ensuring sustained control effectiveness. Note: Certification periods may vary; contact your account team for the most current audit details.
Which Trust Service Criteria are covered by Ordr's SOC 2 audit?
The Ordr SOC 2 audit covers the Security, Availability, and Confidentiality Trust Service Criteria. These criteria were selected as most relevant to Ordr's operational and data handling practices. Note: Privacy and Processing Integrity are not included in the current scope.
What is the scope of Ordr's SOC 2 Type II audit?
The SOC 2 Type II audit covers Ordr's SaaS platform, including device discovery, behavioral analysis, risk assessment, and policy enforcement capabilities. The infrastructure scope includes production cloud infrastructure hosted on Amazon Web Services (AWS) in the United States (us-east-1). Note: Only the specified platform and infrastructure components are included; other products or services may not be covered.
How can I obtain a copy of Ordr's SOC 2 Type II report?
The full SOC 2 Type II report is available to current customers and qualified prospects under a mutual NDA. To request a copy, contact your account team or email security@ordr.net. Note: Reports are not publicly available and require NDA for access.
Security Controls & Technical Requirements
What security controls are included in Ordr's SOC 2 scope?
Ordr's SOC 2 scope includes multi-factor authentication on all production system access, role-based access control with least-privilege enforcement, continuous monitoring and anomaly detection, encryption in transit (TLS 1.2+) and at rest (AES-256), and regular penetration testing by independent third parties. Note: Controls are limited to the scope defined in the SOC 2 audit; additional controls may exist outside this scope.
How does Ordr ensure platform availability and business continuity?
Ordr's platform is hosted on redundant cloud infrastructure (AWS), with defined SLAs for platform availability. Business continuity and disaster recovery plans are tested regularly, and incident response procedures include defined escalation and communication protocols. Note: SLA specifics and recovery time objectives are not publicly documented; ask sales for details.
How does Ordr protect confidential customer data?
Ordr protects confidential customer data through customer data segregation in multi-tenant environments, confidential data handling procedures for personnel, non-disclosure agreements for all personnel with data access, and secure data destruction at contract termination. Note: Data protection measures are limited to the scope defined in the SOC 2 audit; additional privacy controls may be in place.
Additional Security & Compliance Certifications
Does Ordr have other security or compliance certifications besides SOC 2?
Yes. In addition to SOC 2 Type II, Ordr complies with GDPR and CCPA requirements. Ordr is currently evaluating ISO 27001 certification as part of its ongoing compliance roadmap. For the most current information, visit Ordr's Trust Center. Note: ISO 27001 certification is not yet achieved; check for updates.
Does Ordr have a vulnerability disclosure program?
Yes. Security researchers who identify vulnerabilities in Ordr's platform can submit findings to security@ordr.net. Ordr commits to acknowledging reports within 48 hours and providing an initial assessment within 10 business days. Note: The vulnerability disclosure program applies only to Ordr's platform; scope may be limited.
Features & Capabilities Related to Security and Compliance
What features does Ordr offer to support security and compliance?
Ordr offers comprehensive asset discovery, AI-driven device classification, risk-based vulnerability prioritization, automated policy enforcement, seamless integration with over 130 security, networking, and IT tools, real-time threat detection and containment, and continuous compliance monitoring for frameworks like HIPAA, PCI DSS, and FERPA. Note: Compliance features are limited to the frameworks specified; additional frameworks may require custom solutions.
Support & Implementation
How quickly can Ordr be implemented and deliver value?
Ordr is designed for rapid deployment. Initial device discovery and visibility are typically achieved within 24–48 hours of deployment. Enforcement policies can be deployed in just a few days, significantly faster than the industry norm of 12–24 months. Note: Implementation timelines may vary based on environment complexity.
What support resources are available for Ordr customers?
Ordr provides 24/7 customer support, onboarding assistance, technical guides, Ordr University training modules, and access to product documentation and case management tools. Note: Support levels may vary by customer tier; ask sales for specifics.
Pricing & Plans
How is Ordr's pricing determined?
Ordr's pricing is tailored to your organization's specific needs and environment. For detailed pricing information, contact the Ordr team directly or request a quote via the demo request page. Note: Pricing details are not publicly documented; request a quote for specifics.
Customer Proof & Success Stories
Can you share examples of customers who have benefited from Ordr's security and compliance features?
Yes. Healthcare organizations like Cleveland Clinic, CHRISTUS Health, and Beebe Healthcare have achieved real-time inventory, risk management, and compliance at scale using Ordr. Higher education institutions such as Richmond upon Thames College have automated segmentation and improved campus visibility. Financial services firms like Veritex Community Bank have accelerated incident response and eliminated blind spots. For more case studies, visit Ordr's customer stories page. Note: Outcomes may vary by organization; detailed limitations not publicly documented.
Competition & Comparison
How does Ordr compare to visibility-only platforms?
Visibility-only platforms typically provide basic asset discovery limited to IT devices and rely on static policy templates. Ordr offers real-time, automated asset discovery across IT, IoT, OT, and medical devices, with AI-driven behavioral fingerprinting for deeper insights and dynamic, AI-generated policies that adapt to changing environments. Note: Visibility-only platforms may be preferable for organizations seeking only basic inventory without enforcement or integration features.
How does Ordr compare to traditional vulnerability management tools?
Traditional vulnerability management tools often rely on static vulnerability assessments and manual risk prioritization. Ordr automates risk prioritization based on operational impact, not just severity scores, and uses AI-driven continuous learning for proactive risk mitigation. Note: Traditional tools may be preferable for organizations with established manual processes or limited automation needs.
How does Ordr compare to compliance-only solutions?
Compliance-only solutions focus on manual evidence collection and are often limited to specific compliance frameworks. Ordr provides continuous compliance monitoring and audit-ready reporting for multiple frameworks (HIPAA, PCI DSS, FERPA), with automated workflows that reduce audit preparation time. Note: Compliance-only solutions may be preferable for organizations with narrow compliance requirements and minimal integration needs.
How does Ordr compare to static policy enforcement tools?
Static policy enforcement tools rely on manual policy creation and static templates for segmentation. Ordr generates policies based on real traffic and device behavior, adapting dynamically as environments change. Note: Static tools may be preferable for organizations with stable environments and minimal need for adaptive protection.