Compliance & attestations
B5 Secure builds to recognized control frameworks and is progressing through independent attestation. Every item below carries an honest, current status — reports and questionnaires are released under NDA through the document room. We build and operate the controls first; attestation confirms what is already true — and B5’s per-action enforcement writes the audit evidence as it runs.
SOC 2 Type II — Security, Availability, Confidentiality
In progressAn independent examination against the AICPA Trust Services Criteria, evidencing that controls operate effectively over a defined observation period. B5 Secure is in the observation window for Security, Availability, and Confidentiality. The Type I point-in-time design report precedes it. On completion, the full report is available to prospects and customers under NDA.
ISO/IEC 27001:2022 · 27017 · 27018
RoadmapThe international standard for an Information Security Management System, with the 27017 (cloud security) and 27018 (cloud PII) codes of practice. The ISMS scope, risk methodology, and Statement of Applicability are defined; Stage 1 readiness is targeted on the certification roadmap.
ISO/IEC 42001:2023 — AI Management System
RoadmapThe first certifiable standard for governing artificial intelligence responsibly across its lifecycle. B5 Secure’s AI governance program is built to its requirements — model inventory, risk classification, human oversight, and continuous monitoring. See AI Governance.
PCI DSS 4.0
RoadmapThe Payment Card Industry Data Security Standard. B5 Secure is designed to support cardholder-data environments through tokenization, network segmentation, strong cryptography, and least-privilege access — reducing PCI scope for in-scope deployments.
NIST Cybersecurity Framework 2.0
AlignedControls are mapped across all six CSF 2.0 functions — Govern, Identify, Protect, Detect, Respond, and Recover. The newly added Govern function is reflected in our risk-management, supply-chain, and policy program. A control-mapping matrix is available under NDA.
NIST AI Risk Management Framework 1.0
AlignedThe Map, Measure, Manage, and Govern functions are applied to the model lifecycle and to AI-assisted security operations, with the Generative AI Profile (NIST AI 600-1) informing controls on AI-driven features.
GDPR & UK GDPR
Programs in placeProcessing is grounded in a lawful basis with data-minimization and purpose-limitation by design. Data-subject rights are honored through the privacy request workflow. A Data Processing Addendum with Standard Contractual Clauses is available on request.
CCPA / CPRA
Programs in placeCalifornia consumer rights — access, correction, deletion, and opt-out — are supported. B5 Secure does not sell personal information and does not use it for cross-context behavioral advertising.
CSA STAR & CAIQ v4
RoadmapA completed Consensus Assessments Initiative Questionnaire (CAIQ v4) is maintained and shared under NDA. CSA STAR Level 2 attestation is on the roadmap, building on the SOC 2 examination.
FIPS 140-3 Level 3 — validated HSM
Validated moduleSigning and key-wrapping keys are generated and held in an Azure Managed HSM validated to FIPS 140-3 Level 3. This is a property of the cryptographic module in use, with key attestation proving provenance inside the hardware boundary — not an organizational certification. See the cryptography whitepaper.
NIST SSDF (SP 800-218) & SLSA
AlignedThe secure software development lifecycle is aligned to the NIST Secure Software Development Framework, with build provenance targeting SLSA Level 3: signed artifacts, hardened build pipelines, and Software Bills of Materials.
Need a specific report or questionnaire?
SOC 2, CAIQ/SIG, pentest summaries, and policy documents are released under NDA. Request what your review requires and we’ll grant access per document.