DesertSci does not currently hold formal third-party certifications such as SOC 2 or ISO 27001. Rather than a checkbox compliance programme, our security posture is built around the practical controls that these frameworks are designed to verify: role-based access controls, mandatory MFA for administrative access, TLS 1.2+ encryption in transit and encryption at rest, annual third-party penetration testing, and continuous audit logging across client environments. Formal certification against a specific framework can be scoped as part of an engagement where a client's compliance programme requires it. We're also glad to walk any customer's security or procurement team through our controls directly and support a vendor security questionnaire or audit as part of due diligence.