Skip to main content
Wentzel Trust Center
Status: Aligned. Wentzel Investments LLC implements controls for SOC 2 Type 2 + ISO/IEC 27001:2022 but has not yet completed third-party audits. We use "Aligned" never "Compliant" or "Certified".

Security

Security is the mandatory baseline Trust Services Criterion (TSC). Wentzel Investments LLC implements all Common Criteria CC1 through CC9 across the WCB-CC-* unified control catalog. Specific evidence pointers live in the per-repo manifests; this page summarizes the controls applied org-wide.

Common Criteria summary

ControlAreaStatusEvidence
WCB-CC-01Information security policyAligned11 written policies
WCB-CC-06Identity & access — IAM Identity Center + SAMLAlignedAWS IdC + Google SAML
WCB-CC-07MFA — TOTP + WebAuthn (Yubikey 5C NFC)AlignedRequired on all human access
WCB-CC-08Privileged access — break-glass via trustee custodyAlignedGlenda Nicole Ramsey, Trustee Agreement
WCB-CC-11Network security — VPC + WAF + no inboundAlignedphase0-foundation IaC
WCB-CC-12TLS 1.3 in transitAlignedCloudflare edge + ALB
WCB-CC-13KMS at rest — customer-managed keysAlignedPer-data-class CMK
WCB-CC-14Secrets managementAlignedAWS Secrets Manager only
WCB-CC-15Logging & monitoring — CloudTrail + audit-chainAlignedOrg trail + structured app logs
WCB-CC-16Audit trail integrity — Object Lock Compliance modeAligneds3://wentzel-audit-immutable, 7yr SEC 17a-4(f)
WCB-CC-17Change management — PR + CODEOWNERS + signed commitsAlignedGitHub branch protection on every in-scope repo
WCB-CC-18Vulnerability management — Dependabot + CodeQLAlignedCI gates on every PR
WCB-CC-20Incident response — S0–S3 ladder + postmortemsAlignedTabletop annually
WCB-CC-30Secure SDLC — TS strict + ESLint securityAlignedBanned-deps + lint
WCB-CC-31Code review — required PR review + CODEOWNERSAlignedbranch-protection-sanity in WCB Gate
WCB-CC-32Build integrity — SBOM on every artifactAlignedPer-app build pipeline
WCB-CC-43Audit chain emission — every tier-2+ actionOperational@wentzel/audit-chain
WCB-CC-44Object Lock SEC 17a-4(f) — 7-year immutable retentionOperationalProduction bucket armed

External attestation

SOC 2 Type 2 audit is deferred to portfolio batch trigger (first $50K MRR, enterprise customer demand, or cyber-insurer evidence requirement). Nominated auditor: Prescient Assurance.