CyberVault maintains the highest standards of security compliance and regulatory adherence. Explore our certifications, audit reports, and data protection commitments.
Real-time status of our compliance across major industry frameworks and regulations.
Full compliance with SOC 2 Trust Services Criteria covering Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Certified Information Security Management System (ISMS) with 93 controls mapped to Annex A requirements.
Full compliance with EU data protection regulations including data subject rights, breach notification, and cross-border data transfer mechanisms.
Qualified Business Associate (QBA) with full HIPAA Security Rule compliance and HITRUST CSF certification for healthcare data protection.
Full compliance with California privacy laws including consumer rights to access, delete, and opt-out of data sales and sharing.
Currently pursuing FedRAMP Moderate authorization. Security Assessment Contractor (SAC) engagement completed; JAB review in progress.
Detailed breakdown of our compliance status across all frameworks we support.
| Framework | Status | Scope | Last Audit | Next Audit | Certifier |
|---|---|---|---|---|---|
|
SOC 2 Type II
Security, Availability, Confidentiality
|
Certified | Full Platform | March 2025 | March 2026 | Deloitte |
|
ISO 27001:2022
Information Security Management
|
Certified | Full Organization | January 2025 | January 2028 | Bureau Veritas |
|
GDPR
EU Data Protection Regulation
|
Compliant | EU Processing | Ongoing | Continuous | Internal + External |
|
HIPAA / HITRUST
Healthcare Data Protection
|
Certified | Healthcare Services | February 2025 | February 2026 | HITRUST |
|
CCPA / CPRA
California Privacy Rights
|
Compliant | California Residents | Ongoing | Continuous | Internal |
|
PCI DSS 4.0
Payment Card Industry Data Security
|
Compliant | Payment Processing | April 2025 | April 2026 | QSA (Trustwave) |
|
FedRAMP
Federal Security Authorization
|
In Progress | Government Services | SAC Report: Q1 2025 | JAB Review: Q3 2025 | FedRAMP JAB |
|
NIST 800-171
DFAR Cybersecurity Controls
|
In Progress | Defense Services | Assessment Pending | Q4 2025 | C3PAO |
|
UK GDPR / DPA 2018
UK Data Protection
|
Planned | UK Processing | β | Q4 2025 | ICO |
|
PIPEDA
Canadian Privacy Law
|
Planned | Canadian Operations | β | Q1 2026 | OPC Canada |
Our comprehensive data protection strategy ensures your information remains secure throughout its lifecycle.
All data is encrypted using AES-256 encryption at rest and TLS 1.3 for data in transit. Customer-managed encryption keys (CMEK) are available for enterprise clients.
Encryption keys are managed through AWS KMS, Azure Key Vault, or HashiCorp Vault with automatic rotation every 90 days. No shared keys between tenants.
Role-based access control with principle of least privilege. Multi-factor authentication required for all administrative access. Just-in-time access for privileged operations.
Data processing and storage available in US, EU, and APAC regions. Cross-border data transfers use Standard Contractual Clauses (SCCs) and Binding Corporate Rules.
Configurable data retention policies aligned with regulatory requirements. Secure deletion using NIST 800-88 guidelines. Automated data lifecycle management.
Comprehensive audit trails for all data access and modifications. Logs are immutable, tamper-evident, and retained for a minimum of 7 years.
Data is collected through encrypted channels (TLS 1.3) with explicit consent tracking and purpose limitation enforcement.
Automatic classification using DLP scanning β Public, Internal, Confidential, Restricted. Handling rules applied based on sensitivity level.
Data encrypted at rest (AES-256) and stored in geo-redundant, isolated tenant environments. No data mixing between customers.
Processing occurs in isolated, air-gapped environments. PII/PHI processing uses differential privacy and synthetic data where possible.
Automated retention policies based on data classification and regulatory requirements. Anonymization applied after retention period expires.
Cryptographic erasure using key destruction. NIST 800-88 compliant sanitization. Deletion certificates provided upon request.
Access our latest audit reports, certificates, and compliance documentation. Request confidential reports through our secure portal.
Full SOC 2 Type II audit report covering the period January 2024 β December 2024. Unqualified opinion with no exceptions noted.
ISO/IEC 27001:2022 certification certificate for CyberVault's Information Security Management System. Valid until January 2028.
HITRUST Common Security Framework certification covering all HIPAA-relevant controls. Score: 96.8% across 116 controls assessed.
PCI DSS 4.0 compliance attestation covering all payment processing systems. Level 1 merchant compliance achieved.
Internal penetration test results covering application security, infrastructure, and social engineering. All critical findings remediated.
Continuous vulnerability scanning results across all production environments. Current risk score: Low (2.3/10 CVSS).
Review our comprehensive security and privacy policies governing data handling, access, and processing.
Our security team holds industry-leading certifications ensuring the highest level of expertise.
Our ongoing commitment to achieving and maintaining the highest security standards.
Successfully completed surveillance audit with zero non-conformities. Certificate renewed through January 2028.
Deloitte completed SOC 2 Type II audit with unqualified opinion. All 5 Trust Services Criteria met with no exceptions.
Achieved PCI DSS 4.0 compliance with Trustwave QSA. All payment processing systems validated.
Targeting FedRAMP Moderate authorization through JAB process. SAC report submitted, JAB review in progress.
Planning UK GDPR compliance for UK operations and NIST 800-171 for defense contractor requirements.
Targeting PIPEDA compliance for Canadian operations to support growing North American client base.
Request access to our confidential audit reports, security assessments, and compliance certificates through our secure portal.