Openlane Logo

Confidentiality

A Trust Services Criteria category focused on ensuring that only authorized parties can access sensitive information.

Confidentiality is one of the SOC 2 Trust Services Criteria and focuses on making sure that sensitive information is only accessible to authorized parties.

Typical controls include access management, encryption, data classification, and secure data handling practices across the data lifecycle. Breaches of confidentiality can lead to regulatory, contractual, and reputational damage.

When confidentiality is in scope for an audit, organizations must demonstrate both technical safeguards and operational practices that reduce unauthorized access risks.

decorative circle decorative circle decorative circle decorative circle