Compliance & Security
Enterprise-grade compliance. Built in, not bolted on.
Altered Dimensions maintains rigorous compliance with SOC 2, HIPAA, and PCI-DSS frameworks. Every server, every process, every audit — verified and documented.
SOC 2 Type II Compliance
SOC 2 (System and Organization Controls) is a framework developed by the AICPA that ensures service providers securely manage your data. Our Type II audit covers a minimum 6-month observation period, validating that our controls are not just designed properly — but operating effectively over time.
We are audited annually by an independent AICPA-accredited firm. Our SOC 2 report covers all five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Trust Service Criteria Covered
HIPAA Compliance for Healthcare Data
The Health Insurance Portability and Accountability Act (HIPAA) sets the standard for protecting sensitive patient data. Any company that deals with Protected Health Information (PHI) must ensure all required physical, network, and process security measures are in place.
Altered Dimensions offers HIPAA-compliant hosting with a signed Business Associate Agreement (BAA). Our infrastructure meets all HIPAA Security Rule requirements, including administrative, physical, and technical safeguards.
HIPAA Safeguards Implemented
PCI-DSS Level 1 Compliance
The Payment Card Industry Data Security Standard (PCI-DSS) is the global standard for securing payment card data. Level 1 is the highest certification, required for organizations processing over 6 million Visa transactions annually — and the gold standard for any business handling cardholder data.
Our infrastructure undergoes annual on-site assessments by a Qualified Security Assessor (QSA), quarterly network scans by an Approved Scanning Vendor (ASV), and continuous internal monitoring.
PCI-DSS Requirements Met
Infrastructure
Security controls that power compliance.
Encryption
AES-256 at rest. TLS 1.3 in transit. HSM-backed key management with automatic rotation.
Access Control
MFA enforced. SSO/SAML integration. Role-based access with just-in-time provisioning.
Audit Logging
Immutable logs. 90-day retention. SIEM integration with real-time alerting and anomaly detection.
Vulnerability Mgmt
Weekly automated scans. Quarterly penetration tests. 48-hour critical patch SLA.
Network Security
Next-gen firewalls. WAF with OWASP rules. DDoS mitigation up to 1 Tbps.
Incident Response
24/7 SOC monitoring. Documented IR plan. Tabletop exercises quarterly. Breach notification within 24 hours.
Powered by WHMCompleteSolution