Page 3 - C:\Users\ray.durham\Videos\113. SE-Security Overview Program\Mag-SecurityFrm\
P. 3

3. What Reports Are Available?


                 RingCentral Reports
                 Report Type                                   What They Cover
                 RC SOC 2+ (Incl FINRA)                        RingCentral’s service organization controls:
                                                               Security, Availability & Confidentiality
                                                               +
                                                               FINRA cybersecurity rules implemented to
                                                               protect data related to FINRA (financial
                                                               reporting)

                 RC SOC 2+ Incl HIPAA & HITRUST)               RingCentral’s service organization controls:
                                                               Security, Availability & Confidentiality
                                                               +
                                                               HIPAA safeguards implemented to protect
                                                               ePHI data

                 RC Office HITRUST Certificate                 RingCentral Office and the RingCentral app
                                                               have earned Certified status for information
                                                               security by HITRUST. HITRUST CSF certified
                                                               status indicates that these RingCentral apps
                                                               have met industry-defined security
                                                               requirements and are appropriately
                                                               managing risk.

                 PCI DSS Certificate USA (as a merchant)       RingCentral’s self-certification for PCI
                                                               compliance as a merchant. The certificate
                                                               demonstrates the requirements we have in
                                                               place to be PCI certified as a merchant. Note:
                                                               Our service is not PCI certified.

                 PCI AoC USA Report (Attestation of            This is a detailed report that describes our
                 Compliance)                                   setup for collecting credit card data as a
                                                               merchant. Note: This report does not cover
                                                               our service, which is not PCI certified.

                 PCI DSS Certificate UK (as a merchant)        This is RingCentral’s self-certificate for PCI
                                                               compliance as a merchant. The certificate
                                                               demonstrates the requirements we have in
                                                               place to be a PCI certified as a merchant.
                                                               Note: Our service is not PCI certified.




               v3.1 | March 27, 2019         Internal Only | RingCentral Confidential                      2
   1   2   3   4   5   6