Aligned with BIChart's SOC 2 Type II Security Trust Services Criteria
Owner: BIChart Inc.
BIChart maintains a SOC 2 Type II audited control environment designed to protect customer systems, data, and operations.
This Code of Ethics establishes mandatory standards of conduct supporting BIChart's obligations under the SOC 2 Trust Services Criteria for:
All individuals and organizations acting on behalf of BIChart are required to comply with this Code.
SOC 2 Alignment: CC1.1
BIChart operates under principles of honesty, integrity, and ethical business conduct.
Personnel and partners must:
Unethical conduct may result in disciplinary or contractual action.
BIChart requires acknowledgment of ethical standards as part of onboarding and continued engagement.
SOC 2 Alignment: CC1.2, CC1.3
BIChart maintains defined organizational roles, responsibilities, and oversight mechanisms.
Individuals representing BIChart must:
Management oversight ensures ethical and operational accountability across all business activities.
SOC 2 Alignment: CC2.2, CC6
Protection of information assets is a core BIChart control requirement.
All personnel and partners must:
Confidential information includes:
Security incidents or suspected compromise must be reported immediately.
BIChart maintains organization-wide information security policies governing system and data protection.
SOC 2 Alignment: CC6 Logical Access Controls
Users must:
Access privileges are granted based on role and revoked upon termination or role change.
SOC 2 Alignment: CC3, CC7
BIChart performs formal risk assessments and security monitoring processes.
All personnel and partners must:
BIChart maintains defined incident response and escalation procedures supporting system security objectives.
SOC 2 Alignment: Control Environment
Individuals must maintain professional conduct including:
Harassment, intimidation, or retaliation is prohibited.
BIChart promotes open communication and protection against retaliation for good-faith reporting.
SOC 2 Alignment: CC1.5
BIChart holds individuals accountable for internal control responsibilities.
Violations of this Code may result in:
Compliance with ethical and security policies is periodically reaffirmed.
SOC 2 Complementary Controls
Suppliers, affiliates, and partners are considered complementary participants within BIChart's SOC 2 control environment.
Third parties must:
Failure to comply may result in termination of the business relationship.
Concerns may be reported to:
BIChart Compliance
support@bichart.ai
Reports made in good faith will not result in retaliation.
By working with or representing BIChart, individuals and organizations acknowledge adherence to this Code of Ethics and Business Conduct and agree to operate in alignment with BIChart's SOC 2 Type II control environment.