We certify a software supply chain — not a data-processing cloud.
Because B5 Secure ships as libraries that compile into your application and run inside your own cloud, our Trust Center attests to the integrity of what we ship, not to operating a multi-tenant platform that holds your data. That is a shorter, more credible surface — and it is what makes the security review faster.
A library can’t leak data it never receives — so the questions change.
A regulated buyer evaluating a security SaaS must vet a vendor that holds or sees their data: sub-processor disclosure, data-residency review, a new external attack surface. B5 sidesteps that entirely. The relevant assurance for an embedded library is the integrity of the artifact and the pipeline that built it — provenance, a bill of materials, signatures, and reproducibility. This page attests to exactly that.
What B5 attests to in the supply chain.
Each control answers a question a software-supply-chain reviewer actually asks.
SBOM per release
A complete Software Bill of Materials accompanies each release, enumerating components and versions so you can assess and monitor what you compile in.
SLSA Level 3+ provenance
Build provenance proves what was built, from which sources, by which pipeline — tamper-evident from commit to artifact.
Signed NuGet packages
Packages are cryptographically signed so you can verify authenticity and integrity before they enter your build.
Reproducible builds
Builds are reproducible, so an independent rebuild yields the same artifact — the strongest defense against build-time tampering.
Dependency, secret & container scanning
Continuous scanning across dependencies, secrets, and containers in the pipeline, with remediation SLAs.
Pinned, audited dependencies
Dependencies are pinned and hashed, with a preference for audited packages — the application is only as trustworthy as its ground.
How reviewers use this.
Shorter questionnaire
No data-processing means most sub-processor and residency questions do not apply; provenance and SBOM answer the rest.
Verify before you compile
Signatures and SBOM let your team verify authenticity and assess components before they enter your build.
Inherit your boundary
B5 runs inside your certified perimeter; the supply-chain attestations are the surface that remains.
What is validated, and what is on the roadmap.
A smaller, well-scoped surface — stated plainly.
B5’s FIPS 140-3 Level 3 HSM integration is validated today; SOC 2 Type I/II, ISO 27001/42001, PCI DSS, and CSA STAR are progressing on a published roadmap. Because B5 certifies a software supply chain rather than a data cloud, that in-progress status is a smaller surface, not a weakness — and B5 runs inside the boundary your auditors have already certified.
The simplest Trust Center in the category — by design.
Walk your security and compliance team through the supply-chain attestations. The shorter the surface, the faster the close.