Securing 2M+ accounts & $15B+ in assets, protected & secure·B5 Secure™ — per data-element authorization for .NET platforms

Compliance & Attestations

Trust Center  /  Compliance & Attestations
Attestations & frameworks

Compliance & attestations

B5 Secure builds to recognized control frameworks and is progressing through independent attestation. Every item below carries an honest, current status — reports and questionnaires are released under NDA through the document room. We build and operate the controls first; attestation confirms what is already true — and B5’s per-action enforcement writes the audit evidence as it runs.

Achieved In progress Roadmap Aligned (framework)

SOC 2 Type II — Security, Availability, Confidentiality

In progress

An independent examination against the AICPA Trust Services Criteria, evidencing that controls operate effectively over a defined observation period. B5 Secure is in the observation window for Security, Availability, and Confidentiality. The Type I point-in-time design report precedes it. On completion, the full report is available to prospects and customers under NDA.

Evidence: SOC 2 report · bridge letter · available under NDA on completion

ISO/IEC 27001:2022 · 27017 · 27018

Roadmap

The international standard for an Information Security Management System, with the 27017 (cloud security) and 27018 (cloud PII) codes of practice. The ISMS scope, risk methodology, and Statement of Applicability are defined; Stage 1 readiness is targeted on the certification roadmap.

Evidence: ISMS scope · Statement of Applicability · on request

ISO/IEC 42001:2023 — AI Management System

Roadmap

The first certifiable standard for governing artificial intelligence responsibly across its lifecycle. B5 Secure’s AI governance program is built to its requirements — model inventory, risk classification, human oversight, and continuous monitoring. See AI Governance.

Evidence: AI management policy · model register · on request

PCI DSS 4.0

Roadmap

The Payment Card Industry Data Security Standard. B5 Secure is designed to support cardholder-data environments through tokenization, network segmentation, strong cryptography, and least-privilege access — reducing PCI scope for in-scope deployments.

Evidence: segmentation & tokenization design · on request

NIST Cybersecurity Framework 2.0

Aligned

Controls are mapped across all six CSF 2.0 functions — Govern, Identify, Protect, Detect, Respond, and Recover. The newly added Govern function is reflected in our risk-management, supply-chain, and policy program. A control-mapping matrix is available under NDA.

Evidence: CSF 2.0 control-mapping matrix · under NDA

NIST AI Risk Management Framework 1.0

Aligned

The Map, Measure, Manage, and Govern functions are applied to the model lifecycle and to AI-assisted security operations, with the Generative AI Profile (NIST AI 600-1) informing controls on AI-driven features.

Evidence: AI RMF profile · under NDA

GDPR & UK GDPR

Programs in place

Processing is grounded in a lawful basis with data-minimization and purpose-limitation by design. Data-subject rights are honored through the privacy request workflow. A Data Processing Addendum with Standard Contractual Clauses is available on request.

Evidence: DPA + SCCs · records of processing · on request

CCPA / CPRA

Programs in place

California consumer rights — access, correction, deletion, and opt-out — are supported. B5 Secure does not sell personal information and does not use it for cross-context behavioral advertising.

Evidence: privacy policy · DSAR workflow

CSA STAR & CAIQ v4

Roadmap

A completed Consensus Assessments Initiative Questionnaire (CAIQ v4) is maintained and shared under NDA. CSA STAR Level 2 attestation is on the roadmap, building on the SOC 2 examination.

Evidence: CAIQ v4 · under NDA

FIPS 140-3 Level 3 — validated HSM

Validated module

Signing and key-wrapping keys are generated and held in an Azure Managed HSM validated to FIPS 140-3 Level 3. This is a property of the cryptographic module in use, with key attestation proving provenance inside the hardware boundary — not an organizational certification. See the cryptography whitepaper.

Evidence: module validation certificate · key attestation

NIST SSDF (SP 800-218) & SLSA

Aligned

The secure software development lifecycle is aligned to the NIST Secure Software Development Framework, with build provenance targeting SLSA Level 3: signed artifacts, hardened build pipelines, and Software Bills of Materials.

Evidence: SBOM · provenance attestation · under NDA

Need a specific report or questionnaire?

SOC 2, CAIQ/SIG, pentest summaries, and policy documents are released under NDA. Request what your review requires and we’ll grant access per document.

Scroll to Top