ROGUENODE_← BACK TO ROGUENODE_.AI

TRUST CENTER

Security built to a standard — not just claimed.

ROGUENODE_ builds and operates against three independent security frameworks as standing engineering requirements: NIST CSF 2.0, the CSA Cloud Controls Matrix, and OWASP ASVS. Adopting a framework as our baseline is an engineering commitment — it is not the same thing as holding a certification against it. Below is exactly where we stand on each, kept current as our own control register changes.

NIST CSF 2.0

Organizes our security program around Govern, Identify, Protect, Detect, Respond, and Recover.

CSA Cloud Controls Matrix v4

Cloud-specific control coverage — identity, data protection, application security, logging, and incident management.

OWASP ASVS v5

Verifiable, testable application security requirements for everything we ship.

We do not claim certifications we do not hold. No badge or statement on this page represents a completed third-party audit or attestation unless the table below explicitly says so. If a claim on any of our pages ever conflicts with this page, this page is correct — tell us and we'll fix it.

COMPLIANCE STATUS

StandardStatus
SOC 2 Type IIN PROGRESSIn progress — real-time control scoring live, third-party audit not yet started
SOC 2 Type IINOT STARTEDNot started
ISO/IEC 27001NOT STARTEDNot started
GDPRIN PROGRESSPartial — data retention policy in progress
HIPAANOT STARTEDNot applicable — we do not process health data

WHAT'S REAL TODAY

Tenant data is isolated with database-enforced row-level security, running under a restricted database role with no bypass privilege — verified against a real database, not just asserted in policy text.
Data is encrypted in transit (TLS 1.3) and at rest.
Every authenticated request is validated against a live identity record, not a long-lived cached claim.
Security-relevant actions (approvals, alert resolutions, connector changes) write to an append-only audit trail; for high-risk governed actions, a failed audit write blocks the action itself rather than proceeding silently.
AI agents operating inside ROGUENODE_ hold explicit, scoped, revocable capabilities rather than ambient access — least privilege applies to our own automation, not just to human users.
A documented incident-response process exists for credential compromise, cross-tenant exposure, and related scenarios.

WHAT WE'RE ACTIVELY CLOSING

A formal data retention and deletion policy, and a customer-facing deletion/export mechanism.
A documented review process and enforced MFA policy for our own administrative access to production infrastructure.
Tested, verified backup and disaster-recovery procedures with defined recovery objectives.
Third-party vulnerability and dependency scanning is now running in CI; we are working through an initial findings triage before making it a release-blocking gate.

QUESTIONS OR DISCLOSURES

For security questions, compliance documentation requests, or to report a vulnerability, contact security@roguenode.ai.