> ## Documentation Index
> Fetch the complete documentation index at: https://docs.connex.hybridsphere.io/llms.txt
> Use this file to discover all available pages before exploring further.

# SOC 2 Type II & Statutory Compliance

> SOC 2 Type II dual-stage PR deployment gates and enterprise cloud security perimeters

CONNEX Cloud OS and the HybridSphere enterprise ecosystem are audited and engineered to satisfy world-class security benchmarks.

<AccordionGroup>
  <Accordion title="SOC 2 Type II Dual-PR Release Gate (CC8.1/CC8.2)">
    Every code change and infrastructure modification requires a dual-stage review process: Stage 1 Human-In-The-Loop source PR approval in the application repository, followed by Stage 2 declarative Kustomize deployment PR approval in ArgoCD.
  </Accordion>

  <Accordion title="Zero Static JSON Service Account Keys (Workload Identity)">
    Downloading, storing, or committing static GCP service account JSON keys is permanently banned. All Kubernetes pods authenticate dynamically via Workload Identity Federation.
  </Accordion>

  <Accordion title="Cloud Armor WAF & Multi-Region GKE Gateway">
    External traffic traverses Google Cloud Armor WAF security policies and L7 Gateway API endpoints, intercepting DDoS vectors and malicious exploits at the perimeter.
  </Accordion>
</AccordionGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.