SBOMVault
Trust Center

Everything procurement asks about, in one place

Certifications, audit reports, security controls, subprocessors, and contractual artifacts — request a free login to access the full set.

Certifications & frameworks

SOC 2 Type II

In progress

Audit in progress with Schellman; Type II report expected in 2026.

ISO 27001:2022

Planned

On the security roadmap.

ISO 27017 (cloud)

Planned

Planned alongside ISO 27001.

ISO 27018 (cloud privacy)

Planned

Planned alongside ISO 27001.

GDPR

Achieved

Compliant. DPA + Standard Contractual Clauses available.

CCPA / CPRA

Achieved

Compliant. Privacy notice and consumer-rights workflow live.

PCI DSS v4.0 (vendor scope)

In progress

AOC for SAQ A scope expected Q3 2026.

HIPAA / BAA available

Achieved

BAA available for healthcare-scope customers.

EU CRA self-assessment

Achieved

Internal CRA conformity workflow operational; we eat our own dog food.

FedRAMP Moderate

Planned

On the 2027 roadmap. StateRAMP authorization in progress.

Audit reports & documents

Request access to gated reports →

Pen test summary

NDA required

External pen test executive summary, Q1 2026; testing firm disclosed under NDA.

PDF · 1.8 MB

Security & privacy whitepaper

Public

Architecture, controls, and data handling overview.

PDF · 2.4 MB

Subprocessor list

Public

All third parties processing customer data, with country and purpose.

PDF · 120 KB

DPA + SCCs

Public

Data Processing Addendum with EU Standard Contractual Clauses.

PDF · 320 KB

Operational practices

  • Annual independent third-party penetration test + quarterly internal pen tests
  • Continuous SCA + SAST + secrets scanning on our own codebase
  • Vulnerability disclosure program (security@sbomvault.ai)
  • Production access requires MFA + just-in-time elevation, fully logged
  • Documented incident response plan with 24-hour customer notification commitment
  • Daily encrypted backups with point-in-time recovery
  • All code changes require code review + CI security gates before merge
  • Mandatory security review for any change touching auth, encryption, or audit code paths

Need something specific?

Custom security questionnaires, on-site audits, contractual terms — we've done it before. Tell us what you need.

Talk to security