Hello!
We are currently going through our internal procurement and approval process for the DefectDojo Community Edition deployment. As part of this evaluation, our team would like to assess how the Community Edition fits into our ASPM process, with the intent to further evaluate and potentially move to the Pro Edition by the end of this year.
Our Legal and Compliance team has requested a copy of DefectDojo’s SOC 2 attestation as part of their review.
Could somone please help on whom to reach out for the SOC 2 attestation report or supporting documentation for DefectDojo so we can proceed with the internal approval process?