Security & Trust
Independently-attested security across NIST CSF 2.0, ISO 27001:2022, SOC 2 Type II, and CSA CCM v4.
§ 1 — Certifications & frameworks
What we are held to
Each framework below is tracked control-by-control in our compliance system. Coverage figures are computed from the live control assessments, not written by marketing.
NIST Cybersecurity Framework 2.0 - Six Functions: Govern, Identify, Protect, Detect, Respond, Recover. Each Function groups Categories which in turn group Subcategories (controls).
2 of 6 controls implemented (33.3%) · 2 partial · each cell = 1%
Information security, cybersecurity and privacy protection — Information security management systems — Requirements. 2022 revision condenses the 2013 standard's 114 controls into 93 across 4 themes.
0 of 93 controls implemented (0.0%) · 11 partial · each cell = 1%
AICPA SOC 2 examination criteria. Five Trust Services Categories: Security (always in scope), Availability, Processing Integrity, Confidentiality, Privacy. Type I attests design at a point in time; Type II attests operating effectiveness over a period (typically 6–12 months).
0 of 56 controls implemented (0.0%) · 2 partial · each cell = 1%
CSA CCM v4 — cloud-provider-specific control catalog. Ships in the CSA STAR registry as the de facto cloud security baseline. 197 controls grouped into 17 domains spanning governance, architecture, datacenter, cryptography, IAM, supply chain, and incident response.
0 of 197 controls implemented (0.0%) · 39 partial · each cell = 1%
U.S. HIPAA Security Rule for the protection of electronic Protected Health Information (ePHI). Five safeguard categories: Administrative, Physical, Technical, Organizational, and Documentation. Implementation specs are either Required (R) or Addressable (A).
0 of 48 controls implemented (0.0%) · 24 partial · each cell = 1%
Canada's Personal Information Protection and Electronic Documents Act. Federal privacy law applying to organisations engaged in commercial activities — interprovincial, international, and federally-regulated businesses. Enforced by the Office of the Privacy Commissioner of Canada (OPC). Builds on 10 fair-information principles in Schedule 1 + mandatory breach reporting since November 2018.
0 of 32 controls implemented (0.0%) · 3 partial · each cell = 1%
Quebec's modernised privacy regime applicable to enterprises operating in Quebec or processing the personal information of Quebec residents. In force in 3 phases (Sept 2022 / 2023 / 2024). Enforced by the Commission d'accès à l'information du Québec (CAI). Penalties up to $25M or 4% of annual worldwide turnover. Director / officer personal liability.
0 of 35 controls implemented (0.0%) · 7 partial · each cell = 1%
EU General Data Protection Regulation. Applies to processing of personal data of EU residents regardless of where the controller/processor is established (territorial scope, art. 3). Enforced by member-state Data Protection Authorities (DPAs). Penalties up to €20M or 4% of worldwide turnover.
0 of 41 controls implemented (0.0%) · 2 partial · each cell = 1%
§ 4 — Security transparency