Frequently Asked Questions
Answers to common questions about Agilewing.
01 What documentation does Agilewing provide to verify our PCI-DSS compliance posture before we commit?
+
Agilewing delivers a full set of evidence artifacts—including a current SOC 2 Type II report, a PCI-DSS Attestation of Compliance (AOC), and network segmentation diagrams—upon request under NDA. The package also includes a risk‑assessment questionnaire aligned to the PCI 4.0 control set, allowing your QSA to perform a gap analysis before contract signing.
02 How does Agilewing keep our data compliant with China MLPS 2.0 when migrating workloads from Hong Kong to Shenzhen?
+
Agilewing maps each workload to MLPS 2.0 data classifications and deploys the required controls—network isolation, access‑control lists, and encrypted storage—in both regions. Prior to migration, a joint audit verifies that the Shenzhen environment meets the three‑level security requirements, and a compliance report is issued with findings and remediation steps.
03 Can Agilewing show third-party certifications for its managed information-security (MSS) service?
+
Yes. Agilewing holds ISO 27001 and SOC 2 Type II certifications for its MSS platform, and it conducts quarterly independent penetration tests. Clients can request the latest certification reports and test summaries under a standard NDA.
04 What SLA does Agilewing guarantee for CDN latency and uptime, especially for high-traffic cloud-gaming events?
+
Agilewing offers a 99.9% monthly uptime SLA with a 30 ms p95 latency target for its global anycast CDN. When traffic exceeds a predefined burst threshold, the platform automatically scales edge capacity and reroutes requests to the nearest PoP, without requiring manual intervention.
05 Does Agilewing support bring-your-own-key (BYOK) for data-at-rest encryption, and how is the key lifecycle managed?
+
Agilewing integrates with industry-standard HSMs (Azure Key Vault, AWS KMS) so you can supply your own encryption keys. Key rotation, revocation, and audit logging are automated through the MSP portal, and a copy of each key version is stored in a geographically separated backup vault.
06 How does Agilewing handle cross-border data transfers to satisfy GDPR and CCPA requirements for our e-commerce traffic?
+
Agilewing classifies personal data at ingestion, applies TLS encryption in transit, and routes processing to compliant region‑specific clusters. Data‑transfer agreements (DTAs) and Standard Contractual Clauses (SCCs) are embedded in the service contract, and a data‑flow map is provided for GDPR Article 30 records.