REGISTER
Non-compliance log
Breaches, audit findings and policy gaps raised in meetings, with owner and rectification target.2 high-severity open.
| Finding | Reference | Owner | Severity | Rectify by | Status | |
|---|---|---|---|---|---|---|
Stale contractor accounts not disabled 12 contractor accounts remained active past contract end dates. IT Security & SOC-2 Compliance Audit | SOC-2 CC6.2 | Michael Tan delivered+michael.tan@resend.dev | high | OVERDUE 2026-09-17 | open | |
Shared admin credentials on legacy deployment server Credential shared across four engineers; no individual attribution possible. IT Security & SOC-2 Compliance Audit | SOC-2 CC6.1 | Michael Tan delivered+michael.tan@resend.dev | high | 2026-10-02 | open | |
Incident log review not performed weekly The weekly incident-log review was skipped in three of the last eight weeks. IT Security & SOC-2 Compliance Audit | SOC-2 CC7.3 | Sofia Alvarez delivered+sofia.alvarez@resend.dev | medium | 2026-10-02 | open | |
tscheck Compliance Report Filing The tscheck compliance report must be filed to maintain statutory compliance. tscheck-action-persist-fixture | tscheck compliance policy | Arjun Mehta | medium | 2026-12-25 | resolved |