Compliance & Safety

Designed for production environments

Every engagement is scoped, authorized, and audited — and supports PCI, HIPAA, SOC 2, and cyber insurance requirements.

Safety & Authorization

How we keep production systems safe

Scoped and authorized security perimeter illustration
✓Fully scoped & pre-authorized before any testing begins
✓Configurable maintenance windows & rate limiting
✓Full audit trail of every action taken
✓Explicit exclusion lists for sensitive/critical systems
✓Human expert review before any high-impact exploit is attempted
✓Signed authorization agreement required for every engagement
Compliance Alignment

Supports the frameworks you're actually being audited against

PCI DSS

Regular penetration testing requirements for cardholder data environments.

HIPAA

Technical safeguard validation for protected health information systems.

SOC 2

Security control testing evidence for Trust Services Criteria audits.

Cyber Insurance

Documented, continuous testing evidence increasingly required by underwriters.

Certifications

Organizational & Team Credentials

Split shield illustration representing attack and defense balance
ISO/IEC 27001:2022
SOC 2 Type II
🇨🇦 Canadian-Based Security Team

Individual certifications held by members of our security team — MatrixIT is not itself certified by these organizations, our practitioners are.

CISMISACA
OSCPOffSec
AZ-500Microsoft
CISAISACA
CEHEC-Council
CICPCore Impact
Security+CompTIA / DoD 8570.1M
FCNSPFortinet
CCSECheck Point
PCIPCI Security Standards Council
Sophos InfrastructureSophos
Synchronized SecuritySophos

Questions about scope or authorization for your environment?

Talk to Our Team