<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Compliance &amp; Governance on DefectDojo Trust Center</title><link>/policies/compliance_governance/</link><description>Recent content in Compliance &amp; Governance on DefectDojo Trust Center</description><generator>Hugo</generator><language>en-US</language><copyright>Copyright (c) 2020-2024 Thulite</copyright><lastBuildDate>Thu, 08 Jan 2026 00:00:00 +0000</lastBuildDate><atom:link href="/policies/compliance_governance/index.xml" rel="self" type="application/rss+xml"/><item><title>Anti-Corruption &amp; Bribery Policy</title><link>/policies/compliance_governance/defectdojo-anti-corruption-bribery-policy/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>/policies/compliance_governance/defectdojo-anti-corruption-bribery-policy/</guid><description>&lt;h2 id="1-purpose"&gt;1. Purpose&lt;/h2&gt;
&lt;p&gt;DefectDojo, Inc. is committed to conducting its business ethically and in compliance with all applicable laws and regulations, including the U.S. Foreign Corrupt Practices Act (FCPA), the United Kingdom Bribery Act (UKBA) and similar laws in other countries that prohibit improper payments to obtain a business advantage. This document describes DefectDojo, Inc.’s Policy prohibiting bribery and other improper payments in the conduct of DefectDojo, Inc. business operations and employee responsibilities for ensuring implementation of the Policy. Questions about the Policy or its applicability to particular circumstances should be directed to the Head of HR or Chief Executive Officer.&lt;/p&gt;</description></item><item><title>Audit Policy</title><link>/policies/compliance_governance/defectdojo-audit-policy/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>/policies/compliance_governance/defectdojo-audit-policy/</guid><description>&lt;h2 id="1-purpose"&gt;1. Purpose&lt;/h2&gt;
&lt;p&gt;The purpose of this policy is to inform all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations regarding the auditing of all systems, networks, and IT assets for which they are assigned ownership and maintenance.&lt;/p&gt;</description></item><item><title>Completed Fraud Prevention Checklist</title><link>/policies/compliance_governance/defectdojo-completed-fraud-prevention-checklist/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>/policies/compliance_governance/defectdojo-completed-fraud-prevention-checklist/</guid><description>&lt;h2 id="fraud-prevention-checklist"&gt;Fraud Prevention Checklist&lt;/h2&gt;
&lt;p&gt;&lt;em&gt;Completed by Jay Paz 02/24/2025&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Is ongoing anti-fraud training provided to all employees of the organization?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Do employees understand what constitutes fraud?
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Communicated via policy and during team meetings&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Have the costs of fraud to the company and everyone in it – including lost profits, adverse publicity, potential job loss, and decreased morale and productivity – been made clear to employees?
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Communicated via policy and during team meetings&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Do employees know where to seek advice when faced with uncertain ethical decisions, and do they believe that they can speak freely?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Has a policy of zero tolerance for fraud been communicated to employees through words and actions?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Is an effective fraud reporting mechanism in place?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Have employees been taught how to communicate concerns about known or potential wrongdoing?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Is there a reporting channel available to employees?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Do employees trust that they can report suspicious activity anonymously and/or confidentially (where legally permissible) and without fear of reprisal?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Has it been made clear to employees that reports of suspicious activity will be promptly and thoroughly evaluated?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Is continuous monitoring software used to detect fraud and, if so, has the use of such software been made known throughout the organization?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Is the management climate/tone at the top one of honesty and integrity?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Are employees surveyed to determine the extent to which they believe management acts with honesty and integrity?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Are performance goals realistic?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Are strong anti-fraud controls in place and operating effectively, including the following?
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Proper segregation of duties&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Use of authorizations&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Physical safeguards&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Job rotations&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Vacations&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Does the recruitment policy include the following (where permitted by law)?
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Criminal and civil background checks&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Credit checks&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Are employee support programs in place to assist employees struggling with addiction, mental/emotional health, family, or financial problems?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Is an open-door policy in place that allows employees to speak freely about pressures, providing management the opportunity to alleviate such pressures before they become acute?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Are regular, anonymous surveys conducted to assess employee morale?&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Exceptions Policy</title><link>/policies/compliance_governance/defectdojo-exceptions-policy/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>/policies/compliance_governance/defectdojo-exceptions-policy/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;The purpose of this document is to inform all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations regarding requesting exceptions to DefectDojo corporate policies, standards, and procedures.&lt;/p&gt;</description></item><item><title>Fraud Prevention Checklist</title><link>/policies/compliance_governance/defectdojo-fraud-prevention-checklist/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>/policies/compliance_governance/defectdojo-fraud-prevention-checklist/</guid><description>&lt;h1 id="fraud-prevention-checklist"&gt;Fraud Prevention Checklist&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Is ongoing anti-fraud training provided to all employees of the organization?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Do employees understand what constitutes fraud?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Have the costs of fraud to the company and everyone in it – including lost profits, adverse publicity, potential job loss, and decreased morale and productivity – been made clear to employees?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Do employees know where to seek advice when faced with uncertain ethical decisions, and do they believe that they can speak freely?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Has a policy of zero tolerance for fraud been communicated to employees through words and actions?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Is an effective fraud reporting mechanism in place?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Have employees been taught how to communicate concerns about known or potential wrongdoing?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Is there a reporting channel, such as a third-party hotline, available to employees?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Do employees trust that they can report suspicious activity anonymously and/or confidentially (where legally permissible) and without fear of reprisal?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Has it been made clear to employees that reports of suspicious activity will be promptly and thoroughly evaluated?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Do reporting policies and mechanisms extend to vendors, customers, and other outside parties?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; To increase employee perception of detection, are the following proactive measures taken and publicized to employees?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Is possible fraudulent conduct actively sought out, rather than dealt with passively?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Does the organization send the message that it actively seeks out fraudulent conduct through fraud assessment questioning by auditors?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Are surprise fraud audits performed in addition to regularly scheduled audits?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Is continuous monitoring software used to detect fraud and, if so, has the use of such software been made known throughout the organization?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Is the management climate/tone at the top one of honesty and integrity?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Are employees surveyed to determine the extent to which they believe management acts with honesty and integrity?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Are performance goals realistic?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Have fraud prevention goals been incorporated into the performance measures that are used to evaluate managers and to determine performance-related compensation?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Has the organization established, implemented, and tested a process for oversight of fraud risks by the Board of Directors or others charged with governance (e.g., the audit committee)?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Are fraud risk assessments performed to proactively identify and mitigate the company’s vulnerabilities to internal and external fraud?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Are strong anti-fraud controls in place and operating effectively, including:
&lt;ul&gt;
&lt;li&gt;Proper segregation of duties&lt;/li&gt;
&lt;li&gt;Use of authorizations&lt;/li&gt;
&lt;li&gt;Physical safeguards&lt;/li&gt;
&lt;li&gt;Job rotations&lt;/li&gt;
&lt;li&gt;Vacations&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Does the internal audit department, if one exists, have adequate resources and authority to operate effectively and without undue influence from senior management?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Does the recruitment policy include the following (where permitted by law)?
&lt;ul&gt;
&lt;li&gt;Criminal and civil background checks&lt;/li&gt;
&lt;li&gt;Credit checks&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Are employee support programs in place to assist employees struggling with addiction, mental/emotional health, family, or financial problems?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Is an open-door policy in place that allows employees to speak freely about pressures, providing management the opportunity to alleviate such pressures before they become acute?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Are regular, anonymous surveys conducted to assess employee morale?&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Risk Management Policy</title><link>/policies/compliance_governance/defectdojo-risk-management-policy/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>/policies/compliance_governance/defectdojo-risk-management-policy/</guid><description>&lt;h2 id="purpose-of-policy"&gt;Purpose of Policy&lt;/h2&gt;
&lt;p&gt;This policy informs all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations regarding the risk management of all systems, networks, IT assets, and licensed software, owned, operated, or used by DefectDojo.&lt;/p&gt;</description></item><item><title>Risk Management Procedure</title><link>/policies/compliance_governance/defectdojo-risk-management-procedure/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>/policies/compliance_governance/defectdojo-risk-management-procedure/</guid><description>&lt;h2 id="policy-statement"&gt;Policy Statement&lt;/h2&gt;
&lt;p&gt;This procedure supports the DefectDojo Risk Management Policy by providing practical steps for identifying, assessing, treating, monitoring, and reporting risks.&lt;/p&gt;</description></item></channel></rss>