FICTIONAL DOCUMENT-REVIEW EXERCISE — NOT AN AUTHENTIC RECORD All people, organizations, identifiers, legal conclusions, clinical parameters, and events are invented for text retrieval practice. Do not use as professional advice, an authoritative standard, a real filing, or an operational instruction. RECORD 1: CLOUDSCALE TECHNOLOGIES INC. — SOC 2 TYPE II EXAMINATION REPORT INDEPENDENT SERVICE AUDITOR’S REPORT ON CONTROLS RELEVANT TO SECURITY & AVAILABILITY PERIOD COVERED: OCTOBER 1, 2024 TO SEPTEMBER 30, 2025 AUDIT FIRM: KENSINGTON ASSURANCE LLP (SYNTHETIC) ================================================================================ SECTION III: MANAGEMENT’S DESCRIPTION OF CRITERIA AND BOUNDARIES Control Environment & Security Governance CloudScale Technologies operates a multi-tenant cloud storage and analytical data platform deployed across AWS us-east-1 and us-west-2 regions. Management maintains a formalized Information Security Policy reviewed and approved annually. Data Protection, Backup, and Disaster Recovery (Availability Criterion A1.2) Production PostgreSQL databases and customer object stores are replicated across three Availability Zones with automated continuous snapshotting. Full database backups are encrypted at rest utilizing AES-256 and archived to immutable S3 Glacier Vaults. Management’s policy requires quarterly simulated backup restoration testing of sampled production database volumes. Security Incident Triage and Response (Criterion CC7.3) CloudScale maintains a dedicated Security Operations Center (SOC) operating 24/7/365. Potential security alerts are categorized into Severity 1 (Critical) through Severity 4 (Low). Under CloudScale's internal incident response policy (SOP-SEC-402), confirmed Severity 1 incidents involving unauthorized access to customer data require executive escalation within forty-eight (48) hours and customer disclosure within seventy-two (72) hours following root-cause confirmation. SECTION IV: TRUST SERVICES CRITERIA, CONTROLS, AND SERVICE AUDITOR’S TESTS Control CC6.8: Backup Integrity and Restoration Testing Control Activity: Management tests the integrity and recoverability of backup media on a quarterly basis by performing sample restoration tests of production databases to isolated test environments. Service Auditor’s Test: Inspected the quarterly backup restoration test logs for twenty-five (25) randomly sampled production database backup snapshots across the evaluation period. Test Result & Auditor Exception: Exception Noted: For two (2) of the twenty-five (25) sampled backup snapshots (specifically the Q1 snapshot of the EU Analytics Cluster and the Q3 snapshot of the APAC Customer Metadata Cluster), restoration failed due to corrupted snapshot index pointers. Remediation was not completed within the 14-day recovery SLA. Management Response: Management acknowledges the finding. Automated index verification scripts have been deployed to validate future snapshot pointer trees prior to glacier tiering. Control CC7.2: Vulnerability Management and Patching SLAs Control Activity: Critical operating system and package vulnerabilities identified by automated scanners shall be remediated within fourteen (14) days of vendor patch availability. Service Auditor’s Test: Sampled forty (40) critical vulnerability alerts across Linux container hosts. Test Result: No exceptions noted. All sampled critical vulnerabilities were patched within an average of 8.4 days.