TRUST CENTER
Security built to a standard — not just claimed.
ROGUENODE_ builds and operates against three independent security frameworks as standing engineering requirements: NIST CSF 2.0, the CSA Cloud Controls Matrix, and OWASP ASVS. Adopting a framework as our baseline is an engineering commitment — it is not the same thing as holding a certification against it. Below is exactly where we stand on each, kept current as our own control register changes.
NIST CSF 2.0
Organizes our security program around Govern, Identify, Protect, Detect, Respond, and Recover.
CSA Cloud Controls Matrix v4
Cloud-specific control coverage — identity, data protection, application security, logging, and incident management.
OWASP ASVS v5
Verifiable, testable application security requirements for everything we ship.
COMPLIANCE STATUS
| Standard | Status |
|---|---|
| SOC 2 Type I | IN PROGRESSIn progress — real-time control scoring live, third-party audit not yet started |
| SOC 2 Type II | NOT STARTEDNot started |
| ISO/IEC 27001 | NOT STARTEDNot started |
| GDPR | IN PROGRESSPartial — data retention policy in progress |
| HIPAA | NOT STARTEDNot applicable — we do not process health data |
WHAT'S REAL TODAY
WHAT WE'RE ACTIVELY CLOSING
QUESTIONS OR DISCLOSURES
For security questions, compliance documentation requests, or to report a vulnerability, contact security@roguenode.ai.
