================================================================================ CLOUDSCALE TECHNOLOGIES — SOC 2 TYPE II & ENTERPRISE MSA AUDIT TEST PACK FOR TESTING OFFLINE / LOCAL THIRD-PARTY VENDOR RISK & NDA COMPLIANCE WORKFLOWS ================================================================================ NOTICE: This is a fictional test corpus prepared for third-party risk management (TPRM), vendor security auditing, SOC 2 assessment, and AI grounding evaluations. All company names, audit firms, control numbers, and legal covenants are entirely synthetic and do not depict real corporate entities. ================================================================================ ================================================================================ RECORD 1: CLOUDSCALE TECHNOLOGIES INC. — SOC 2 TYPE II EXAMINATION REPORT INDEPENDENT SERVICE AUDITOR’S REPORT ON CONTROLS RELEVANT TO SECURITY & AVAILABILITY PERIOD COVERED: OCTOBER 1, 2024 TO SEPTEMBER 30, 2025 AUDIT FIRM: KENSINGTON ASSURANCE LLP (SYNTHETIC) ================================================================================ SECTION III: MANAGEMENT’S DESCRIPTION OF CRITERIA AND BOUNDARIES Control Environment & Security Governance CloudScale Technologies operates a multi-tenant cloud storage and analytical data platform deployed across AWS us-east-1 and us-west-2 regions. Management maintains a formalized Information Security Policy reviewed and approved annually. Data Protection, Backup, and Disaster Recovery (Availability Criterion A1.2) Production PostgreSQL databases and customer object stores are replicated across three Availability Zones with automated continuous snapshotting. Full database backups are encrypted at rest utilizing AES-256 and archived to immutable S3 Glacier Vaults. Management’s policy requires quarterly simulated backup restoration testing of sampled production database volumes. Security Incident Triage and Response (Criterion CC7.3) CloudScale maintains a dedicated Security Operations Center (SOC) operating 24/7/365. Potential security alerts are categorized into Severity 1 (Critical) through Severity 4 (Low). Under CloudScale's internal incident response policy (SOP-SEC-402), confirmed Severity 1 incidents involving unauthorized access to customer data require executive escalation within forty-eight (48) hours and customer disclosure within seventy-two (72) hours following root-cause confirmation. SECTION IV: TRUST SERVICES CRITERIA, CONTROLS, AND SERVICE AUDITOR’S TESTS Control CC6.8: Backup Integrity and Restoration Testing Control Activity: Management tests the integrity and recoverability of backup media on a quarterly basis by performing sample restoration tests of production databases to isolated test environments. Service Auditor’s Test: Inspected the quarterly backup restoration test logs for twenty-five (25) randomly sampled production database backup snapshots across the evaluation period. Test Result & Auditor Exception: Exception Noted: For two (2) of the twenty-five (25) sampled backup snapshots (specifically the Q1 snapshot of the EU Analytics Cluster and the Q3 snapshot of the APAC Customer Metadata Cluster), restoration failed due to corrupted snapshot index pointers. Remediation was not completed within the 14-day recovery SLA. Management Response: Management acknowledges the finding. Automated index verification scripts have been deployed to validate future snapshot pointer trees prior to glacier tiering. Control CC7.2: Vulnerability Management and Patching SLAs Control Activity: Critical operating system and package vulnerabilities identified by automated scanners shall be remediated within fourteen (14) days of vendor patch availability. Service Auditor’s Test: Sampled forty (40) critical vulnerability alerts across Linux container hosts. Test Result: No exceptions noted. All sampled critical vulnerabilities were patched within an average of 8.4 days. ================================================================================ RECORD 2: ENTERPRISE CLOUD SERVICES MASTER AGREEMENT (EXCERPT) CUSTOMER: APEX FINANCIAL ENTERPRISES LLC | VENDOR: CLOUDSCALE TECHNOLOGIES INC. EXECUTION DATE: JANUARY 14, 2025 ================================================================================ SECTION 9: CONFIDENTIALITY, SECURITY, AND DATA BREACH NOTIFICATION Section 9.2. Security Incident Notification SLA In the event Vendor discovers or reasonably suspects any unauthorized access, breach, exfiltration, or compromise of Customer Confidential Information or Customer Personal Data ("Security Incident"), Vendor shall notify Customer in writing within twenty-four (24) hours of initial discovery or suspicion. Vendor shall provide a preliminary root-cause summary and an active mitigation plan within forty-eight (48) hours. Section 9.5. Backup and Recovery Guarantee (RTO & RPO) Vendor guarantees a Recovery Point Objective (RPO) of not more than one (1) hour and a Recovery Time Objective (RTO) of not more than four (4) hours for all Customer Data. Vendor warrants that 100% of production data backups are validated and recoverable. SECTION 12: LIMITATION OF LIABILITY AND INDEMNIFICATION Section 12.1. Aggregate Liability Cap Except as provided in Section 12.4, each party’s maximum aggregate liability arising out of or related to this Agreement shall be limited to the total fees paid by Customer in the twelve (12) months preceding the incident ("Standard Cap"). Section 12.4. Uncapped Liabilities & Super-Cap The limitations in Section 12.1 shall NOT apply to: (a) Vendor's breach of Section 9 (Confidentiality and Security), (b) gross negligence or willful misconduct, or (c) Vendor's third-party IP indemnification obligations.