Everything procurement asks about, in one place
Certifications, audit reports, security controls, subprocessors, and contractual artifacts — request a free login to access the full set.
Certifications & frameworks
SOC 2 Type II
In progressAudit in progress with Schellman; Type II report expected in 2026.
ISO 27001:2022
PlannedOn the security roadmap.
ISO 27017 (cloud)
PlannedPlanned alongside ISO 27001.
ISO 27018 (cloud privacy)
PlannedPlanned alongside ISO 27001.
GDPR
AchievedCompliant. DPA + Standard Contractual Clauses available.
CCPA / CPRA
AchievedCompliant. Privacy notice and consumer-rights workflow live.
PCI DSS v4.0 (vendor scope)
In progressAOC for SAQ A scope expected Q3 2026.
HIPAA / BAA available
AchievedBAA available for healthcare-scope customers.
EU CRA self-assessment
AchievedInternal CRA conformity workflow operational; we eat our own dog food.
FedRAMP Moderate
PlannedOn the 2027 roadmap. StateRAMP authorization in progress.
Audit reports & documents
Request access to gated reports →Pen test summary
NDA requiredExternal pen test executive summary, Q1 2026; testing firm disclosed under NDA.
PDF · 1.8 MB
Security & privacy whitepaper
PublicArchitecture, controls, and data handling overview.
PDF · 2.4 MB
Subprocessor list
PublicAll third parties processing customer data, with country and purpose.
PDF · 120 KB
DPA + SCCs
PublicData Processing Addendum with EU Standard Contractual Clauses.
PDF · 320 KB
Operational practices
- ✓Annual independent third-party penetration test + quarterly internal pen tests
- ✓Continuous SCA + SAST + secrets scanning on our own codebase
- ✓Vulnerability disclosure program (security@sbomvault.ai)
- ✓Production access requires MFA + just-in-time elevation, fully logged
- ✓Documented incident response plan with 24-hour customer notification commitment
- ✓Daily encrypted backups with point-in-time recovery
- ✓All code changes require code review + CI security gates before merge
- ✓Mandatory security review for any change touching auth, encryption, or audit code paths
Need something specific?
Custom security questionnaires, on-site audits, contractual terms — we've done it before. Tell us what you need.
Talk to security