SAS 70 Compliance
SAS 70 stands for “Statement on Auditing Standards” by the American Institute of Certified Public Accountants (AICPA), and it determines the professional standards a service auditor uses in a formal report to measure the internal controls of a service organization.
DataSpan was the first Data Storage Solutions company to gain SAS 70 compliance, through the security verification of every step of our servo track media certification and data eradication processes. And with the introduction of the Sarbanes-Oxley Act, this certification is more important than ever. With DataSpan, you can rest assured, that you are “doing business on the straight and narrow.” A copy of our SAS 70 Audit file is available upon request.
To learn more about the SAS 70 process, please read our FAQ section below.
FAQs: SAS 70 Audit Questions & Answers
What is an SAS 70 Audit?
SAS 70 Compliance recognizes that a service organization has been through an in-depth audit of their control activities, which generally include controls over information technology and related processes. In today's global economy, service organizations or outsourcing providers must demonstrate that they have adequate controls and safeguards when they handle data belonging to their customers. In addition, the requirements of the Sarbanes-Oxley Act and Health Insurance Portability and Accountability Act (HIPAA) make SAS 70 audit reports even more important to the process of reporting on effective internal controls at service organizations.
SAS 70 is the authoritative guidance that allows service organizations to disclose their control activities and processes to their customers and their customers' auditors in a uniform reporting format. A SAS 70 audit signifies that a service organization has had its control objectives and activities examined by an independent accounting and auditing firm.
Why is this important to Datacenter managers?
Anyone concerned about data security should be interested in an SAS 70 Audit. If you are part of a publicly traded company that must comply with Sarbanes-Oxley or HIPAA, this focus on security is further amplified. Many companies require SAS 70 compliance for their service providers and companies to which they outsource operations. When we provide data eradication services to a customer, whether buying their used media or just eradicating and certifying their tapes, we are subject to SAS 70 requirements.
SAS 70 compliance provides you with reassurance that your tapes, and the data on them, are being handled by service professionals that have a clearly defined and secure process for data eradication. You should never settle for a service provider that does not have SAS 70 compliance.
What is a SAS 70 Type II audit report?
At the conclusion of a SAS 70 audit, a formal report including the auditor's opinion (“Service Auditor's Report”) is issued to the service organization. This is one of the most effective ways a service organization can communicate information about its processes and controls. A Type II report not only includes the service organization's description of controls and processes, but also includes detailed testing of the service organization's controls by an independent auditor.
What products and services does our SAS 70 Type II Audit cover?
The SAS 70 audit was conducted on our processing of servo tape media: 3590, 3590E, 9840, 9940, and LTO 1, LTO 2 and LTO 3 products. Our SAS 70 compliance applies to our data eradication processes including activities at the customer's location, transportation to the Operations Center, and the processing that takes place in our Secure Operations Center in Dallas.
These processes apply to the following product and service offerings:
- Tape Buyback Program
- DataSpan 100% Certified Tape (3590, 3590E, 9840, 9940, LTO 1, LTO 2 and LTO 3 only)
- Data Eradication and Tape Disposal Service
Who performed our SAS 70 Type II audit?
Weaver and Tidwell, L.L.P, ranked the largest regional public accounting firm in the Southwest, is among "the Top 100" in the nation. Weaver and Tidwell conducted our SAS 70 audit.
Find Clarity in Storage
DataSpan offers a wide array of Data Storage Solutions, including:
Disk Storage,
SAN Management,
Tape Storage,
Tape Buyback Program,
Tape Storage and Transport,
Data Duplication and Format Conversion,
Tape Labeling and Initialization,
Tape Disposal,
Data Eradication and Data Destruction,
Tape Cleaning and Certification,
Tape Library Audits,
Tape Library Relocations and Configurations,
Disaster Recovery,
Tape Removal and Reslotting,
Asset Recycling, and
RFID Tape and Asset Tracking.





