FICTIONAL DOCUMENT-REVIEW EXERCISE — NOT AN AUTHENTIC RECORD
All people, organizations, identifiers, legal conclusions, clinical parameters,
and events are invented for text retrieval practice. Do not use as professional
advice, an authoritative standard, a real filing, or an operational instruction.

RECORD 1: CLOUDSCALE TECHNOLOGIES INC. — SOC 2 TYPE II EXAMINATION REPORT
INDEPENDENT SERVICE AUDITOR’S REPORT ON CONTROLS RELEVANT TO SECURITY & AVAILABILITY
PERIOD COVERED: OCTOBER 1, 2024 TO SEPTEMBER 30, 2025
AUDIT FIRM: KENSINGTON ASSURANCE LLP (SYNTHETIC)
================================================================================

SECTION III: MANAGEMENT’S DESCRIPTION OF CRITERIA AND BOUNDARIES

Control Environment & Security Governance
CloudScale Technologies operates a multi-tenant cloud storage and analytical data 
platform deployed across AWS us-east-1 and us-west-2 regions. Management maintains 
a formalized Information Security Policy reviewed and approved annually. 

Data Protection, Backup, and Disaster Recovery (Availability Criterion A1.2)
Production PostgreSQL databases and customer object stores are replicated across 
three Availability Zones with automated continuous snapshotting. Full database backups 
are encrypted at rest utilizing AES-256 and archived to immutable S3 Glacier Vaults. 
Management’s policy requires quarterly simulated backup restoration testing of sampled 
production database volumes.

Security Incident Triage and Response (Criterion CC7.3)
CloudScale maintains a dedicated Security Operations Center (SOC) operating 24/7/365. 
Potential security alerts are categorized into Severity 1 (Critical) through Severity 4 
(Low). Under CloudScale's internal incident response policy (SOP-SEC-402), confirmed 
Severity 1 incidents involving unauthorized access to customer data require executive 
escalation within forty-eight (48) hours and customer disclosure within seventy-two (72) 
hours following root-cause confirmation.


SECTION IV: TRUST SERVICES CRITERIA, CONTROLS, AND SERVICE AUDITOR’S TESTS

Control CC6.8: Backup Integrity and Restoration Testing
Control Activity:
Management tests the integrity and recoverability of backup media on a quarterly basis 
by performing sample restoration tests of production databases to isolated test environments.

Service Auditor’s Test:
Inspected the quarterly backup restoration test logs for twenty-five (25) randomly sampled 
production database backup snapshots across the evaluation period.

Test Result & Auditor Exception:
Exception Noted: For two (2) of the twenty-five (25) sampled backup snapshots (specifically 
the Q1 snapshot of the EU Analytics Cluster and the Q3 snapshot of the APAC Customer Metadata 
Cluster), restoration failed due to corrupted snapshot index pointers. Remediation was not 
completed within the 14-day recovery SLA.
Management Response:
Management acknowledges the finding. Automated index verification scripts have been deployed 
to validate future snapshot pointer trees prior to glacier tiering.


Control CC7.2: Vulnerability Management and Patching SLAs
Control Activity:
Critical operating system and package vulnerabilities identified by automated scanners 
shall be remediated within fourteen (14) days of vendor patch availability.

Service Auditor’s Test:
Sampled forty (40) critical vulnerability alerts across Linux container hosts.

Test Result:
No exceptions noted. All sampled critical vulnerabilities were patched within an average 
of 8.4 days.
