Status: Aligned. Wentzel Investments LLC implements controls for SOC 2 Type 2 + ISO/IEC 27001:2022 but has not yet completed third-party audits. We use "Aligned" never "Compliant" or "Certified".
Security
Security is the mandatory baseline Trust Services Criterion (TSC). Wentzel Investments LLC implements all Common Criteria CC1 through CC9 across the WCB-CC-* unified control catalog. Specific evidence pointers live in the per-repo manifests; this page summarizes the controls applied org-wide.
Common Criteria summary
| Control | Area | Status | Evidence |
|---|---|---|---|
| WCB-CC-01 | Information security policy | Partial | Written policy set |
| WCB-CC-06 | Identity & access — IAM Identity Center + SAML | Aligned | Identity Center rollout in progress (GRC-17, PLAT-73); static IAM users being retired (SEC-21) |
| WCB-CC-07 | MFA — TOTP + WebAuthn (Yubikey 5C NFC) | Aligned | Required on all human access |
| WCB-CC-08 | Privileged access — break-glass via trustee custody | Aligned | Glenda Nicole Ramsey, Trustee Agreement |
| WCB-CC-11 | Network security — VPC + WAF + no inbound | In progress | Runner-fleet SG (module-managed, no ingress in IaC); vault SG not in IaC; Cloudflare WAF status unverified (GRC-41) |
| WCB-CC-12 | TLS 1.3 in transit | Aligned | Cloudflare edge + ALB |
| WCB-CC-13 | KMS at rest — customer-managed keys | Aligned | Per-data-class CMK |
| WCB-CC-14 | Secrets management | Operational | AWS Secrets Manager only |
| WCB-CC-15 | Logging & monitoring — CloudTrail + audit-chain | Operational | Org trail + structured app logs |
| WCB-CC-16 | Audit trail integrity — durable WORM store + long-term retention | In progress | Hash-chain via @wentzel/audit-chain; durable s3://wentzel-audit-immutable/ pending operator apply of tools/evidence-pipeline (SEC-81) — not live |
| WCB-CC-17 | Change management — PR + CODEOWNERS (signed commits not enforced) | Partial | GitHub branch protection on every in-scope repo; signed commits are not required |
| WCB-CC-18 | Vulnerability management — Dependabot + scanners | Partial | Dependabot multi-ecosystem + scanner workflows; SLA in Jira |
| WCB-CC-20 | Incident response — S0–S3 ladder + postmortems | Out of repo | Incident-response runbook; annual tabletop not yet on file |
| WCB-CC-30 | Secure SDLC — TS strict + ESLint security | Aligned | Banned-deps + lint |
| WCB-CC-31 | Code review — required PR review + CODEOWNERS | Partial | branch-protection-sanity in WCB Gate |
| WCB-CC-32 | Build integrity — SBOM on every artifact | Partial | Per-app build pipeline |
| WCB-CC-43 | Audit chain emission — hash-chained, append-only | In progress | @wentzel/audit-chain; durable D1 store rolling out |
| WCB-CC-44 | WORM retention SEC 17a-4(f) — long-term immutable storage | Planned | Terraform apply-ready at tools/evidence-pipeline (Object Lock COMPLIANCE, 7yr); bucket not provisioned until operator apply (SEC-81) |
External attestation
SOC 2 Type 2 audit is deferred to portfolio batch trigger (first $50K MRR, enterprise customer demand, or cyber-insurer evidence requirement). Nominated auditor: Prescient Assurance.