Securing 2M+ accounts & $15B+ in assets, protected & secure·B5 Secure™ — per data-element authorization for .NET platforms

Software Supply Chain Security

Trust Center · Software Supply Chain

We certify a software supply chain — not a data-processing cloud.

Because B5 Secure ships as libraries that compile into your application and run inside your own cloud, our Trust Center attests to the integrity of what we ship, not to operating a multi-tenant platform that holds your data. That is a shorter, more credible surface — and it is what makes the security review faster.

SBOM per releaseSLSA Level 3+ provenanceSigned NuGet packagesReproducible builds
Why this matters

A library can’t leak data it never receives — so the questions change.

A regulated buyer evaluating a security SaaS must vet a vendor that holds or sees their data: sub-processor disclosure, data-residency review, a new external attack surface. B5 sidesteps that entirely. The relevant assurance for an embedded library is the integrity of the artifact and the pipeline that built it — provenance, a bill of materials, signatures, and reproducibility. This page attests to exactly that.

The B5 approach

What B5 attests to in the supply chain.

Each control answers a question a software-supply-chain reviewer actually asks.

SBOM per release

A complete Software Bill of Materials accompanies each release, enumerating components and versions so you can assess and monitor what you compile in.

SLSA Level 3+ provenance

Build provenance proves what was built, from which sources, by which pipeline — tamper-evident from commit to artifact.

Signed NuGet packages

Packages are cryptographically signed so you can verify authenticity and integrity before they enter your build.

Reproducible builds

Builds are reproducible, so an independent rebuild yields the same artifact — the strongest defense against build-time tampering.

Dependency, secret & container scanning

Continuous scanning across dependencies, secrets, and containers in the pipeline, with remediation SLAs.

Pinned, audited dependencies

Dependencies are pinned and hashed, with a preference for audited packages — the application is only as trustworthy as its ground.

Where it earns its place

How reviewers use this.

Vendor risk

Shorter questionnaire

No data-processing means most sub-processor and residency questions do not apply; provenance and SBOM answer the rest.

AppSec

Verify before you compile

Signatures and SBOM let your team verify authenticity and assess components before they enter your build.

Audit

Inherit your boundary

B5 runs inside your certified perimeter; the supply-chain attestations are the surface that remains.

Honest framing

What is validated, and what is on the roadmap.

A smaller, well-scoped surface — stated plainly.

B5’s FIPS 140-3 Level 3 HSM integration is validated today; SOC 2 Type I/II, ISO 27001/42001, PCI DSS, and CSA STAR are progressing on a published roadmap. Because B5 certifies a software supply chain rather than a data cloud, that in-progress status is a smaller surface, not a weakness — and B5 runs inside the boundary your auditors have already certified.

Related

The simplest Trust Center in the category — by design.

Walk your security and compliance team through the supply-chain attestations. The shorter the surface, the faster the close.

Scroll to Top