Skip to Content

Security & Trust

Independently-attested security across NIST CSF 2.0, ISO 27001:2022, SOC 2 Type II, and CSA CCM v4.

● LIVE generated from compliance records 2026-10-03 09:15 UTC sealed sha256:911c89372f36ede970686f1c7856b567fbd1d8748915f85341b072dd7ceb1439

§ 1 — Certifications & frameworks

What we are held to

Each framework below is tracked control-by-control in our compliance system. Coverage figures are computed from the live control assessments, not written by marketing.

NIST Cybersecurity Framework 2.0 Aligned (self-attested)

audited by Patrii Cloud Internal Audit · period ending 2027-04-24

NIST Cybersecurity Framework 2.0 - Six Functions: Govern, Identify, Protect, Detect, Respond, Recover. Each Function groups Categories which in turn group Subcategories (controls).

2 of 6 controls implemented (33.3%) · 2 partial · each cell = 1%

ISO/IEC 27001:2022 Audit in Progress

audited by BSI Group (anticipated)

Information security, cybersecurity and privacy protection — Information security management systems — Requirements. 2022 revision condenses the 2013 standard's 114 controls into 93 across 4 themes.

0 of 93 controls implemented (0.0%) · 11 partial · each cell = 1%

SOC 2 (Trust Services Criteria) Aligned (self-attested)

AICPA SOC 2 examination criteria. Five Trust Services Categories: Security (always in scope), Availability, Processing Integrity, Confidentiality, Privacy. Type I attests design at a point in time; Type II attests operating effectiveness over a period (typically 6–12 months).

0 of 56 controls implemented (0.0%) · 2 partial · each cell = 1%

CSA Cloud Controls Matrix v4 Aligned (self-attested)

CSA CCM v4 — cloud-provider-specific control catalog. Ships in the CSA STAR registry as the de facto cloud security baseline. 197 controls grouped into 17 domains spanning governance, architecture, datacenter, cryptography, IAM, supply chain, and incident response.

0 of 197 controls implemented (0.0%) · 39 partial · each cell = 1%

HIPAA Security Rule Aligned (self-attested)

U.S. HIPAA Security Rule for the protection of electronic Protected Health Information (ePHI). Five safeguard categories: Administrative, Physical, Technical, Organizational, and Documentation. Implementation specs are either Required (R) or Addressable (A).

0 of 48 controls implemented (0.0%) · 24 partial · each cell = 1%

PIPEDA (Canada Federal) Aligned (self-attested)

Canada's Personal Information Protection and Electronic Documents Act. Federal privacy law applying to organisations engaged in commercial activities — interprovincial, international, and federally-regulated businesses. Enforced by the Office of the Privacy Commissioner of Canada (OPC). Builds on 10 fair-information principles in Schedule 1 + mandatory breach reporting since November 2018.

0 of 32 controls implemented (0.0%) · 3 partial · each cell = 1%

Quebec Law 25 (Loi 25) Aligned (self-attested)

Quebec's modernised privacy regime applicable to enterprises operating in Quebec or processing the personal information of Quebec residents. In force in 3 phases (Sept 2022 / 2023 / 2024). Enforced by the Commission d'accès à l'information du Québec (CAI). Penalties up to $25M or 4% of annual worldwide turnover. Director / officer personal liability.

0 of 35 controls implemented (0.0%) · 7 partial · each cell = 1%

GDPR (EU 2016/679) Aligned (self-attested)

EU General Data Protection Regulation. Applies to processing of personal data of EU residents regardless of where the controller/processor is established (territorial scope, art. 3). Enforced by member-state Data Protection Authorities (DPAs). Penalties up to €20M or 4% of worldwide turnover.

0 of 41 controls implemented (0.0%) · 2 partial · each cell = 1%

§ 4 — Security transparency

The numbers, unedited

0
reportable privacy breaches, last 12 months
GENERATED FROM LIVE COMPLIANCE DATA · 2026-10-03 09:15 UTC · SEALED SHA-256 911c89372f36ede9… (2026-07-05) · security.txt (RFC 9116)