Revision September 5, 2026 · Evidence review
ISO 27001 Self-Attested · 93 Controls · Statement of Applicability

ISO 27001, self-attested.

A review inventory covering 93 Annex A control topics, plus related cloud and privacy areas. The rows identify evidence to collect, not independently accepted operating controls.

No certification, approved audit schedule or completed Statement of Applicability is established by this page.

ISO/IEC 27002:2022 93 Annex A controls 4 themes + 27017 cloud + 27701 privacy + Beyond-ISO cryptographic controls
Self-attestation disclosure: read before proceeding

This is a self-maintained review inventory, not an ISO certificate or independent audit. Operational status is open unless supported by the review evidence. Earlier certification targets are withdrawn pending approval.

Framework Context

Why ISO 27001 in addition to SOC 2.

The two frameworks are complementary, not redundant. Regional procurement requirements and buyer sophistication determine which frameworks matter most to a given reviewer.

SOC 2

SOC 2 (AICPA)

  • American Institute of Certified Public Accountants standard
  • US-centric; most common in North American enterprise procurement
  • Produces an attestation report, not a certificate
  • Trust Service Criteria: Security, Availability, Confidentiality, Processing Integrity, Privacy
  • Type 1: design at a point in time; Type 2: operating effectiveness over the agreed examination period
  • Widely required by US enterprise security review processes and procurement teams
SOC 2 self-attested posture →
ISO 27001

ISO 27001 (ISO/IEC)

  • International Organization for Standardization / International Electrotechnical Commission
  • Global standard; required in EU, APAC, Middle East, and many government procurement contexts
  • Produces a certificate issued by an accredited certification body
  • Information Security Management System (ISMS) framework; requires continual improvement
  • Stage 1 (documentation review) + Stage 2 (implementation audit) certification process
  • Many EU and Asia-Pacific procurement teams require ISO; many US teams require SOC 2; sophisticated buyers ask for both
ISO/IEC 27001:2022 standard →

Our dual-framework approach: We map our controls to both frameworks so a reviewer in any region can map us to their internal control framework. The underlying security controls are identical. This page and the SOC 2 self-attested page are two views of the same control inventory, written in the vocabulary each framework uses. Sources: ISO/IEC 27002:2022 and ISO/IEC 27001:2022.

ISO/IEC 27002:2022 Structure

The four control themes.

ISO/IEC 27002:2022 reorganized the control framework from 14 domains (in the 2013 edition) to 4 themes covering all 93 controls. Source: ISO/IEC 27002:2022.

Theme 5 37 controls

Organizational

Review organizational scope, accountable owners and dated operating records. See the itemized evidence requests below.

Theme 6 8 controls

People

Review people scope, accountable owners and dated operating records. See the itemized evidence requests below.

Theme 7 14 controls

Physical

Review physical scope, accountable owners and dated operating records. See the itemized evidence requests below.

Theme 8 34 controls

Technological

Review technological scope, accountable owners and dated operating records. See the itemized evidence requests below.

Statement of Applicability

All 93 Annex A controls.

Control summaries are reviewer navigation, not the standard's exact text or an auditor's finding. Each row identifies a required check. Evidence open means that operating effectiveness or applicability has not been established in this review.

5

Organizational Controls

37 controls · A.5.1 to A.5.37
Control Title ISO Description Our Implementation Status
A.5.1 Policies for information security Information security policy and topic-specific policies defined, approved by management, published, communicated, and reviewed at planned intervals. Approve a versioned information-security policy and record review ownership. Evidence open
A.5.2 Information security roles and responsibilities Information security roles and responsibilities defined and allocated according to the information security policy. Name accountable security owners and accepted delegates. Evidence open
A.5.3 Segregation of duties Conflicting duties and areas of responsibility segregated to reduce opportunities for unauthorized or unintentional modification or misuse. Test non-founder administrative recovery and document conflicting duties. Evidence open
A.5.4 Management responsibilities Management requires all personnel to apply information security in accordance with established policy and procedures. Record management approval and periodic security review decisions. Evidence open
A.5.5 Contact with authorities Appropriate contacts with relevant authorities maintained. Maintain verified authority contacts and escalation criteria. Evidence open
A.5.6 Contact with special interest groups Appropriate contacts with special interest groups or security forums maintained. Document relevant security-community participation and responsible owner. Evidence open
A.5.7 Threat intelligence Information relating to information security threats collected and analyzed to produce threat intelligence. Retain threat-intelligence reviews and resulting remediation decisions. Evidence open
A.5.8 Information security in project management Information security integrated into project management throughout the project lifecycle. Attach security requirements and risk decisions to project records. Evidence open
A.5.9 Inventory of information and other associated assets Inventory of information and other associated assets maintained and identified, with ownership established. Reconcile the source/hosting inventory with credentials, data stores and owners. Evidence open
A.5.10 Acceptable use of information and other associated assets Rules for acceptable use and procedures for handling information and other associated assets identified, documented, and implemented. Approve acceptable-use rules and record acknowledgement. Evidence open
A.5.11 Return of assets Personnel and other interested parties return all organizational assets upon change or termination of employment, contract, or agreement. Track device return, access removal and custody on departure. Evidence open
A.5.12 Classification of information Information classified according to information security needs based on confidentiality, integrity, availability, and relevant stakeholder requirements. Classify payloads, receipt metadata, identifiers, telemetry and exports separately. Evidence open
A.5.13 Labelling of information Appropriate set of procedures for information labelling developed and implemented in accordance with the information classification scheme. Verify sensitivity labels across receipt, log and export schemas. Evidence open
A.5.14 Information transfer Formal transfer policies, procedures, and controls in place to protect information transferred within the organization and to external parties. Test transport for edge, origin and outbound calls; the legacy IP lookup uses HTTP. Evidence open
A.5.15 Access control Rules to control physical and logical access to information and other associated assets established and implemented. Review deployed authorization, administrator membership and least privilege. Evidence open
A.5.16 Identity management Full lifecycle of identities managed. Identities uniquely assigned. Shared identities prohibited except when approved and documented. Reconcile identity lifecycle and service-account ownership. Evidence open
A.5.17 Authentication information Allocation and management of authentication information controlled by a management process. Application signing keys enter process memory; no KMS custody is established. Evidence open
A.5.18 Access rights Access rights to information and other associated assets provisioned, reviewed, modified, and removed following access control policy. Record access approvals, review decisions and deprovisioning tests. Evidence open
A.5.19 Information security in supplier relationships Processes and procedures defined and implemented to manage information security risks associated with use of supplier products or services. Confirm the complete processor inventory and supplier risk assessments. Evidence open
A.5.20 Addressing security in supplier agreements Relevant security requirements established and agreed with each supplier based on the type of supplier relationship. Obtain executed agreements, data roles and service-specific transfer terms. Evidence open
A.5.21 Managing security in the ICT supply chain Processes and procedures defined and implemented to manage information security risks associated with ICT products and services supply chain. Review dependencies, build provenance and supplier change risks. Evidence open
A.5.22 Monitoring, review and change management of supplier services Organization regularly monitors, reviews and manages changes to supplier services. Retain supplier monitoring results and approved change decisions. Evidence open
A.5.23 Information security for use of cloud services Processes for acquisition, use, management, and exit from cloud services established in accordance with information security requirements. Four reviewed Render services use Oregon compute; storage and edge differ. Evidence open
A.5.24 Information security incident management planning and preparation Organization plans and prepares for managing information security incidents by defining incident management processes, roles, and responsibilities. Approve the incident outline, contacts and notification decision process. Evidence open
A.5.25 Assessment and decision on information security events Organization assesses information security events and decides if they are classified as incidents. Define incident severity criteria and retain triage decisions. Evidence open
A.5.26 Response to information security incidents Information security incidents responded to in accordance with documented procedures. Exercise response actions and notification delivery against agreed commitments. Evidence open
A.5.27 Learning from information security incidents Knowledge gained from information security incidents used to strengthen and improve security controls. Record root causes, corrective actions and approved follow-up dates. Evidence open
A.5.28 Collection of evidence Organization establishes and implements procedures for identification, collection, acquisition and preservation of evidence. Define evidence custody, integrity checks and lawful collection limits. Evidence open
A.5.29 Information security during disruption Organization plans how to maintain information security at an appropriate level during disruption. Verify access and security controls during a founder-unavailability drill. Evidence open
A.5.30 ICT readiness for business continuity ICT readiness planned, implemented, maintained, and tested based on business continuity objectives and ICT continuity requirements. Document recovery objectives and test restoration with retained evidence. Evidence open
A.5.31 Legal, statutory, regulatory, and contractual requirements Legal, statutory, regulatory, and contractual requirements relevant to information security identified, documented, and kept up to date. Verify entity, applicable laws, contracts and approved retention schedules. Evidence open
A.5.32 Intellectual property rights Organization implements appropriate procedures to protect intellectual property rights. Maintain license obligations and signed intellectual-property assignments. Evidence open
A.5.33 Protection of records Records protected from loss, destruction, falsification, unauthorized access, and unauthorized release in accordance with legal, regulatory, contractual, and business requirements. Identify authoritative stores, replica handling and backup protection. Evidence open
A.5.34 Privacy and protection of personally identifiable information Organization identifies and meets requirements for preserving privacy and protection of PII according to applicable laws and regulations. Carnac processes text; site telemetry includes identifiers and browsing metadata. Evidence open
A.5.35 Independent review of information security Organization's approach to managing information security and its implementation reviewed independently at planned intervals or when significant changes occur. No independent audit report or executed engagement was supplied. Evidence open
A.5.36 Compliance with policies, rules, and standards for information security Compliance with information security policies, rules, and standards regularly reviewed and, if necessary, corrective actions taken. Collect policy-compliance checks, exceptions and corrective-action records. Evidence open
A.5.37 Documented operating procedures Operating procedures for information processing facilities documented and made available to personnel who need them. Approve operating procedures and demonstrate that delegates can execute them. Evidence open
6

People Controls

8 controls · A.6.1 to A.6.8
Control Title ISO Description Our Implementation Status
A.6.1 Screening Background verification checks carried out on all candidates for employment and contractors prior to engagement, proportional to role and risk. Verify screening scope and records for authorized personnel. Evidence open
A.6.2 Terms and conditions of employment Employment contractual agreements state personnel's and organization's responsibilities for information security. Obtain accepted employment or contractor security obligations. Evidence open
A.6.3 Information security awareness, education, and training Personnel and relevant interested parties receive appropriate information security awareness, education, and training. Retain training completion records and role-specific security instruction. Evidence open
A.6.4 Disciplinary process Formal and communicated disciplinary process in place to take action against personnel who have committed an information security policy violation. Approve the personnel policy and its applicable escalation process. Evidence open
A.6.5 Responsibilities after termination or change of employment Information security responsibilities and duties that remain valid after termination or change of employment defined, communicated, and enforced. Verify post-termination duties and tested access revocation. Evidence open
A.6.6 Confidentiality or non-disclosure agreements Confidentiality or NDA requirements reflecting the organization's needs for protection of information identified, documented, reviewed regularly, and signed by personnel and other interested parties. Review executed confidentiality agreements and their coverage. Evidence open
A.6.7 Remote working Security measures implemented when personnel work remotely to protect information accessed, processed, or stored outside the organization's premises. Assess workstation, network and remote-access configurations. Evidence open
A.6.8 Information security event reporting Organization provides a mechanism for personnel to report observed or suspected information security events through appropriate channels and in a timely manner. Test event-reporting channels and record escalation ownership. Evidence open
7

Physical Controls

14 controls · A.7.1 to A.7.14
Control Title ISO Description Our Implementation Status
A.7.1 Physical security perimeters Security perimeters defined and used to protect areas containing information and other associated assets. Document workstation and hosting physical-security responsibility boundaries. Evidence open
A.7.2 Physical entry Secure areas protected by appropriate entry controls and access points. Verify authorized physical entry arrangements within Hive's own scope. Evidence open
A.7.3 Securing offices, rooms, and facilities Physical security designed and applied to offices, rooms, and facilities. Assess office equipment and workspace protection. Evidence open
A.7.4 Physical security monitoring Premises monitored continuously for unauthorized physical access. Confirm monitoring scope without publishing private location details. Evidence open
A.7.5 Protecting against physical and environmental threats Protection against physical and environmental threats, such as natural disasters and other intentional or unintentional physical threats, designed and implemented. Collect environmental protection and power-continuity test records. Evidence open
A.7.6 Working in secure areas Security measures for working in secure areas designed and implemented. Document secure-work-area practices and permitted access. Evidence open
A.7.7 Clear desk and clear screen Clear desk rules applied to papers and removable storage media, and clear screen rules applied to information processing facilities. Verify clear-screen and unattended-device controls. Evidence open
A.7.8 Equipment siting and protection Equipment sited securely and protected. Assess equipment placement and protection against loss or damage. Evidence open
A.7.9 Security of assets off-premises Off-premises assets protected. Verify device encryption, remote recovery and off-premises custody. Evidence open
A.7.10 Storage media Storage media managed through its full life cycle of acquisition, use, transportation, and disposal according to classification scheme and handling requirements. Inventory removable media and approved handling/disposal methods. Evidence open
A.7.11 Supporting utilities Information processing facilities protected from failures in supporting utilities. Document utility dependencies and tested backup arrangements. Evidence open
A.7.12 Cabling security Cables carrying power, data, or supporting information services protected from interception, interference, or damage. Assess cabling protection within the operating scope. Evidence open
A.7.13 Equipment maintenance Equipment maintained correctly to ensure continued availability and integrity. Record maintenance authority, service access and return checks. Evidence open
A.7.14 Secure disposal or re-use of equipment Items of equipment containing storage media verified to ensure sensitive data and licensed software removed or securely overwritten prior to disposal or re-use. Require disposal records and verification of approved sanitization. Evidence open
8

Technological Controls

34 controls · A.8.1 to A.8.34
Control Title ISO Description Our Implementation Status
A.8.1 User endpoint devices Information stored on, processed by, or accessible via user endpoint devices protected. Verify device encryption, patching, malware protection and inventory. Evidence open
A.8.2 Privileged access rights Allocation and use of privileged access rights restricted and managed. Check administrator MFA and access membership for each active platform. Evidence open
A.8.3 Information access restriction Access to information and application system functions restricted in accordance with the access control policy. Test tenant binding and object-level authorization across endpoints. Evidence open
A.8.4 Access to source code Read and write access to source code, development tools, and software libraries managed appropriately to prevent unauthorized changes. Review repository permissions and accepted change-review rules. Evidence open
A.8.5 Secure authentication Secure authentication technologies and procedures implemented based on information access restrictions. Test each authentication path and service credential lifecycle. Evidence open
A.8.6 Capacity management Use of resources monitored and adjusted in line with current and expected capacity requirements. Measure capacity, saturation alerts and service-specific limits. Evidence open
A.8.7 Protection against malware Protection against malware implemented and supported by appropriate user awareness. Collect endpoint protection configuration and update records. Evidence open
A.8.8 Management of technical vulnerabilities Information about technical vulnerabilities of information systems obtained in a timely manner; exposure evaluated; appropriate measures taken. Record vulnerability reviews, remediation and exception ownership. Evidence open
A.8.9 Configuration management Configurations (including security configurations) of hardware, software, services, and networks established, documented, implemented, monitored, and reviewed. Reconcile deployed settings with reviewed configuration baselines. Evidence open
A.8.10 Information deletion Information stored in information systems, devices, or other storage media deleted when no longer required. Approve class-specific deletion methods; signed statements do not prove all-copy erasure. Evidence open
A.8.11 Data masking Data masking used in accordance with the organization's topic-specific policy on access control and other related policies and business requirements, with applicable legislation. Test masking of identifiers, submitted text and upstream error details. Evidence open
A.8.12 Data leakage prevention Data leakage prevention measures applied to systems, networks, and other devices that process, store, or transmit sensitive information. Review payload egress, telemetry fields and export authorization. Evidence open
A.8.13 Information backup Backup copies of information, software, and systems maintained and tested regularly in accordance with the agreed backup policy. No approved backup schedule or restoration test was supplied. Evidence open
A.8.14 Redundancy of information processing facilities Information processing facilities implemented with redundancy sufficient to meet availability requirements. One countersigner worker has a persistent disk; failover is not established. Evidence open
A.8.15 Logging Logs recording activities, exceptions, faults, and other relevant events produced, stored, protected, and analyzed. Site/legacy telemetry includes personal data; review log fields and retention. Evidence open
A.8.16 Monitoring activities Networks, systems, and applications monitored for anomalous behavior; appropriate actions taken to evaluate potential information security incidents. Test alert rules, recipient delivery and coverage gaps. Evidence open
A.8.17 Clock synchronization Clocks of information processing systems synchronized to approved time sources. Verify clock configuration and measured timestamp accuracy. Evidence open
A.8.18 Use of privileged utility programs Use of utility programs that might be capable of overriding system and application controls restricted and tightly controlled. Review privileged tools, authorized operators and auditability. Evidence open
A.8.19 Installation of software on operational systems Procedures and measures implemented to securely manage software installation on operational systems. Review deployment permissions, immutable revision records and rollback tests. Evidence open
A.8.20 Networks security Networks and network devices secured, managed, and controlled to protect information in systems and applications. Test edge controls and direct-origin exposure. Evidence open
A.8.21 Security of network services Security mechanisms, service levels, and service requirements of network services identified, implemented, and monitored. Check per-host TLS, HSTS and outbound transport configuration. Evidence open
A.8.22 Segregation of networks Groups of information services, users, and information systems segregated in networks. Verify network separation and tenant isolation rather than assuming it. Evidence open
A.8.23 Web filtering Access to external websites managed to reduce exposure to malicious content. Review endpoint filtering needs and deployed coverage. Evidence open
A.8.24 Use of cryptography Rules for effective use of cryptography, including cryptographic key management, defined and implemented. Ed25519 and ML-DSA-65 paths are software signing; no applicable validation certificate supplied. Evidence open
A.8.25 Secure development lifecycle Rules for secure development of software and systems established and applied. Attach security review and test evidence to the actual release. Evidence open
A.8.26 Application security requirements Information security requirements identified, specified, and approved when developing or acquiring applications. Specify authentication, data handling and failure-state requirements per endpoint. Evidence open
A.8.27 Secure system architecture and engineering principles Principles for engineering secure systems established, documented, maintained, and applied to any information system development and integration activities. Review trust boundaries, stored data and fail-open behavior. Evidence open
A.8.28 Secure coding Secure coding principles applied to software development. Inspect injection, encoding, secret handling and dependency risks. Evidence open
A.8.29 Security testing in development and acceptance Security testing processes defined and implemented in the development lifecycle. Run scoped positive/negative tests and preserve results. Evidence open
A.8.30 Outsourced development Organization supervises and monitors the activities related to outsourced system development. Verify development agreements, access limits and code ownership. Evidence open
A.8.31 Separation of development, test, and production environments Development, testing, and production environments separated and secured. Inspect environment separation and use synthetic test data. Evidence open
A.8.32 Change management Changes to information processing facilities and information systems subject to change management procedures. Match approved changes to deployed revisions and rollback plans. Evidence open
A.8.33 Test information Test information appropriately selected, protected, and managed. Review test-data origin, access, retention and disposal. Evidence open
A.8.34 Protection of information systems during audit testing Audit tests and other assurance activities involving assessment of operational systems planned and agreed upon to minimize disruptions to business processes. Authorize audit scope and avoid live personal data or secret collection. Evidence open

The 93 Annex A topic rows cover organizational, people, physical and technological areas. Coverage in this table is not control acceptance or certification.

ISO/IEC 27017:2015

Cloud-specific security extensions.

Cloud extensions organize the shared-responsibility review. Render compute is verified in Oregon for four services; edge, storage and processor scope differ. review evidence.

Control Title Our Cloud Posture (Cloudflare + Render + AWS S3) Status
CLD.6.3.1 Shared roles & responsibilities Allocate cloud security responsibilities in the actual agreement. Evidence open
CLD.8.1.5 Removal of cloud service customer assets Approve deletion across cloud stores, replicas, backups and customer exports. Evidence open
CLD.9.5.1 Segregation in virtual computing environments Test tenant isolation and provider-managed separation assumptions. Evidence open
CLD.9.5.2 Virtual machine hardening Review runtime hardening and the provider/customer responsibility boundary. Evidence open
CLD.12.1.5 Administrator operational security Verify cloud administrator access, MFA and audited recovery. Evidence open
CLD.12.4.5 Monitoring of cloud services Collect cloud monitoring configuration and alert-delivery tests. Evidence open
CLD.13.1.4 Alignment of security management for virtual and physical networks Assess edge, service origin and outbound network controls together. Evidence open
CLD.6.3.1 (CSP) Information security policy for cloud services Approve the cloud-service security policy and data-handling scope. Evidence open
ISO/IEC 27701:2019

Privacy information management extensions.

Privacy roles and applicable requirements depend on the contracting entity, service and agreement. This page does not establish ISO 27701 alignment. See the privacy notice.

27701 · Controller

PII processing purpose limitation

Identify necessary fields and permitted purposes for each endpoint. Carnac receives readable request/output text; hashing-only paths differ.

27701 · Controller

Data subject rights

Rights requests require identity checks and an applicable-law review. The privacy notice distinguishes GDPR response timing from general service targets.

27701 · Processor

Processor vs. controller distinction

Verify controller/processor roles and executed processing agreements for the relevant entity and customer.

27701 · Both

Minimal data collection by default

Do not assume hashes-only storage or PII-free logs. Review classification metadata, telemetry, inspection records, backups and exports separately.

27701 · Processor

Sub-processor management for privacy

Verify processor agreements, onward recipients, regions and customer notice terms.

27701 · Both

Privacy impact assessment

Assess whether a privacy impact review or DPIA is required and retain the decision and mitigation evidence.

ISO/IEC 27036

Supplier relationship security.

Supplier assurance remains a review task, not a completed alignment claim. Hosting and supplier scope.

27036 · Supplier Identification

Sub-processor enumeration

Reconcile configured data paths with all active recipients and their approved purposes.

27036 · Risk Assessment

Supplier risk evaluation

Collect supplier review records, current assurance reports and region/backup evidence.

27036 · Agreement

Contractual security obligations

Verify executed terms for incidents, audit rights, deletion, onward transfers and liability.

ISO/IEC 42001:2023

AI management system alignment.

ISO/IEC 42001:2023 is the international standard for AI management systems (AIMS), published December 2023. It covers AI governance, risk management, and the responsible development and use of AI systems. Source: ISO/IEC 42001:2023.

42001 · AI Governance

Council-of-models architecture

Document AI system roles, model authority and human decision points. A multi-model design alone does not establish a management-system control.

42001 · AI Risk

Provenance scoring (R3 to R6)

Define the meaning and limitations of any provenance labels; test that receipt fields match the service output.

42001 · AI Transparency

Model identity disclosure

Review the actual model-provider path and data flow. Carnac's optional semantic reader uses a configured compute endpoint.

42001 · AI Controls

Human-in-the-loop for Restricted outputs

Verify review gates, exception handling and audit records. No ISO 42001 certification or approved completion date is established.

Beyond ISO

Product-specific evidence boundaries.

These technical review topics supplement the control inventory. They do not imply that an ISO certificate guarantees, excludes or validates any particular implementation.

Beyond-ISO · B.1

Post-quantum cryptography readiness (FIPS 203/204)

What it is

The reviewed services do not all use hybrid signatures.

Why ISO misses it

Ed25519 and ML-DSA-65 have separate service and verifier boundaries.

How we implement

Typed API, receipt/Carnac and countersigner paths use Ed25519. The dedicated signer implements ML-DSA-65 in software.

Verification

signing boundaries. A self-test is not a CAVP or CMVP certificate.

Beyond-ISO · B.2

Cryptographic algorithm transparency

What it is

Algorithm disclosure must identify the exact service, revision and signing path.

Why ISO misses it

A standards name does not establish a validated module or protected key boundary.

Production algorithm list

Inspected keys enter application memory from environment values, local files or generated key material.

Verification

review evidence records the software custody matrix and remaining configuration checks.

Beyond-ISO · B.3

Substrate-level entropy provenance (NIST SP 800-90B + Wave-Lattice cosmic axes)

What it is

No hardware entropy provenance or validated entropy-source evidence was supplied.

Why ISO misses it

A software assertion about entropy is not a hardware attestation.

How we implement

Key generation and entropy sources require per-path review, especially optional QPuF modes.

Verification

Do not infer NIST validation from metadata, algorithm labels or a self-test page.

Beyond-ISO · B.4

Open-source verifier (off-infrastructure verification)

What it is

Customer-held verification depends on the receipt format, verifier code and trusted issuer key.

Why ISO misses it

Independent operation must be demonstrated without a required Hive lookup.

How we implement

Retain signed bytes, dependencies, keys and any optional inclusion evidence before an outage.

Verification

Use the browser verifier only for its supported format and test dependencies.

Beyond-ISO · B.5

SLSA 3 build provenance attestations

What it is

Deployed source revisions were reviewed; that is not a SLSA level determination.

Why ISO misses it

Source lineage is distinct from reproducible build and runtime integrity evidence.

How we implement

No applicable build-level assessment or complete attestation chain was supplied.

Verification

Build provenance scope and acceptance tests remain to be established; earlier target dates are withdrawn.

Beyond-ISO · B.6

Public incident transparency

What it is

Incident transparency requires an approved publication policy and actual records.

Why ISO misses it

Contractual and legal notification obligations need case-specific review.

How we implement

The security page contains an outline, not a verified five-day publication SLA.

Verification

Incident response review.

Beyond-ISO · B.7

On-chain settlement attestation (Base 8453)

What it is

A payment transaction is distinct from a receipt signature or evidence anchor.

Why ISO misses it

Anchoring, if selected, needs a defined commitment, destination and verification method.

How we implement

No promise is made that every receipt or commercial transaction is anchored.

Verification

Verify signature authenticity separately from payment or inclusion evidence; retain trusted keys and checkpoints.

Beyond-ISO · B.8

Customer-controllable cryptographic deletion proof endpoint

What it is

A signed deletion record authenticates the signer's statement and identified scope.

Why ISO misses it

It does not prove that all backups, replicas, caches or exports were removed.

How we implement

No universal deletion endpoint, 72-hour all-copy guarantee or dual-signature deletion format is established.

Verification

retention inventory lists open schedule, hold, method and verification requirements.

FIPS Alignment

Federal cryptographic standards mapping.

A self-test exercises code; CAVP validates algorithm implementations and CMVP validates modules. No applicable Hive certificate was supplied.

Standard Name Our Posture Status
FIPS 140-3 Cryptographic Module Validation No applicable Hive module certificate, approved operating environment or validated custody boundary was supplied. Not established
FIPS 203 ML-KEM (Module-Lattice-Based KEM) ML-KEM is key encapsulation, not signing. No deployment or approved migration date was established. Not established
FIPS 204 ML-DSA (Module-Lattice-Based DSA) The dedicated signer implements ML-DSA-65 in application memory. Other reviewed signing services use Ed25519; no universal hybrid format. Not established
FIPS 205 SLH-DSA (SPHINCS+) No deployed SLH-DSA path or approved adoption schedule was established. Not established
NIST SP 800-90B Entropy Source Validation No applicable entropy-source validation report or certificate was supplied. Not established
NIST SP 800-208 Stateful Hash-Based Signatures (XMSS, LMS) No deployed XMSS or LMS path was established; review state management before any adoption. Not established
Framework Mapping

SOC 2 ↔ ISO 27001 quick reference.

This thematic cross-reference is a navigation aid, not equivalence, applicability approval or a substitute for an auditor's mapping.

SOC 2 Criteria SOC 2 Topic ISO 27002:2022 Controls Notes
CC6.1 Logical and physical access controls A.8.2 + A.8.3 + A.5.15 + A.5.16 + A.5.18 Privileged access, information access restriction, access control policy, identity management, access rights
CC6.2 Prior to issuance of system credentials and prior to user access A.5.17 + A.5.16 + A.6.1 + A.6.2 Authentication information management, identity management, screening, terms of employment
CC7.4 Incident response A.5.24 + A.5.25 + A.5.26 + A.5.27 + A.5.28 Incident planning, event assessment, incident response, learning from incidents, evidence collection
CC8.1 Change management A.8.32 + A.8.19 + A.8.25 + A.8.31 Change management, software installation, secure SDLC, separation of environments
CC9.1 Vendor and business partner risk management A.5.19 + A.5.20 + A.5.21 + A.5.22 Supplier information security, supplier agreements, ICT supply chain, supplier monitoring
CC5.2 Cryptographic controls A.8.24 Use of cryptography; algorithm policy, key management, rotation cadence
A1.2 Availability: Recovery objectives A.8.13 + A.8.14 + A.5.29 + A.5.30 Backup, redundancy, security during disruption, ICT readiness for continuity
P4.1 Privacy: Data subject rights A.5.34 + ISO 27701 PII protection mapped to ISO 27701 privacy extensions; data subject rights endpoints
Evidence Room

Control evidence references.

The table identifies records to request, not evidence already held or available under NDA. Public review observations are in the review evidence.

Control Evidence Type Location / Description Last Reviewed
A.5.1Policy documentRequest policy document with scope, owner and dated results. Availability not verified.Open
A.5.7Threat intel logRequest threat intel log with scope, owner and dated results. Availability not verified.Open
A.5.9Asset registerRequest asset register with scope, owner and dated results. Availability not verified.Open
A.5.15Access matrixRequest access matrix with scope, owner and dated results. Availability not verified.Open
A.5.17Credential policyRequest credential policy with scope, owner and dated results. Availability not verified.Open
A.5.19Sub-processor DPAsRequest sub-processor dpas with scope, owner and dated results. Availability not verified.Open
A.5.24IR RunbookRequest ir runbook with scope, owner and dated results. Availability not verified.Open
A.5.28Evidence proceduresRequest evidence procedures with scope, owner and dated results. Availability not verified.Open
A.5.31Legal registerRequest legal register with scope, owner and dated results. Availability not verified.Open
A.5.35Audit engagementRequest audit engagement with scope, owner and dated results. Availability not verified.Open
A.6.1Screening recordsRequest screening records with scope, owner and dated results. Availability not verified.Open
A.6.2Contract templatesRequest contract templates with scope, owner and dated results. Availability not verified.Open
A.6.6NDA logRequest nda log with scope, owner and dated results. Availability not verified.Open
A.7.5UPS receiptRequest ups receipt with scope, owner and dated results. Availability not verified.Open
A.7.9MDM configRequest mdm config with scope, owner and dated results. Availability not verified.Open
A.8.2FIDO2 configRequest fido2 config with scope, owner and dated results. Availability not verified.Open
A.8.5Auth event logRequest auth event log with scope, owner and dated results. Availability not verified.Open
A.8.7AV configurationRequest av configuration with scope, owner and dated results. Availability not verified.Open
A.8.8Vuln recordsRequest vuln records with scope, owner and dated results. Availability not verified.Open
A.8.13Backup logRequest backup log with scope, owner and dated results. Availability not verified.Open
A.8.15Log samplesRequest log samples with scope, owner and dated results. Availability not verified.Open
A.8.19Deploy recordsRequest deploy records with scope, owner and dated results. Availability not verified.Open
A.8.21HSTS + CSPRequest hsts + csp with scope, owner and dated results. Availability not verified.Open
A.8.24ACVP resultsRequest acvp results with scope, owner and dated results. Availability not verified.Open
A.8.25SAST resultsRequest sast results with scope, owner and dated results. Availability not verified.Open
A.8.31Env separationRequest env separation with scope, owner and dated results. Availability not verified.Open
B.1PQ implementationRequest pq implementation with scope, owner and dated results. Availability not verified.Open
B.4Verifier codeRequest verifier code with scope, owner and dated results. Availability not verified.Open
B.7On-chain anchorsRequest on-chain anchors with scope, owner and dated results. Availability not verified.Open
B.8Deletion certsRequest deletion certs with scope, owner and dated results. Availability not verified.Open
Honest Timeline

Certification roadmap.

Engagements, external assessments and dates require owner approval. No completed agreement or approved certification schedule was supplied.

Open
Date unapproved

ISO 27001 Self-Attested Posture Published

Confirm scope, accountable owner and supporting agreement before publishing a target or completion claim.

Open
Date unapproved

SOC 2 Type 1 Audit Engagement Evidence Request

Confirm scope, accountable owner and supporting agreement before publishing a target or completion claim.

Open
Date unapproved

SOC 2 Type 1 Report Review

Confirm scope, accountable owner and supporting agreement before publishing a target or completion claim.

Open
Date unapproved

SOC 2 Type 2 Observation Scope

Confirm scope, accountable owner and supporting agreement before publishing a target or completion claim.

Open
Date unapproved

ISO 27001 Third-Party Certification

Confirm scope, accountable owner and supporting agreement before publishing a target or completion claim.

Open
Date unapproved

ISO 27017 + 27701 Extensions

Confirm scope, accountable owner and supporting agreement before publishing a target or completion claim.

Open
Date unapproved

FedRAMP Moderate

Confirm scope, accountable owner and supporting agreement before publishing a target or completion claim.

For Reviewers

How to use this page today.

Use this inventory to scope a review and request evidence. Decisions remain with the responsible reviewer and the applicable contract.

01

Interim attestation

Use this inventory to identify the services and control records your review needs. It is not an independent assurance report.

02

Internal gap analysis

Compare the evidence requests with your own requirements and separately determine applicability and acceptance.

03

Request specific evidence

Request the specific records and control IDs at security@thehiveryiq.com. Availability and delivery dates require confirmation.

04

Vendor questionnaire reference

Reference this page as a source-and-evidence review, not a certification or guarantee of operating effectiveness.

FAQ

Common questions.

Is self-attested equivalent to a certified ISO 27001?
No. This inventory is maintained by Hive and is not an independent certificate. It identifies source observations and records still needed.
Why not engage an ISO 27001 audit firm immediately?
No executed ISO engagement, approved scope or assessment schedule was supplied. This page does not impose a fixed observation period or promise an audit date.
Does this page satisfy our security review process?
Your reviewer decides what evidence is sufficient. Specify the service, data classes and required controls when requesting a questionnaire or records.
How do you reconcile this page with the SOC 2 self-attestation page?
The SOC 2 inventory organizes related review topics differently. The mapping is a navigation aid, not proof of equivalent requirements or completed controls.
Where is your Statement of Applicability (SoA)?
An approved Statement of Applicability was not supplied. The topic table is not represented as a completed SoA, and machine-readable delivery is not guaranteed.
Can our auditor speak directly with your security team?
Request a scoped discussion at security@thehiveryiq.com. Participants, material availability and timing require confirmation.
How do you prevent this page from drifting away from reality?
The review evidence records this revision, observations and limitations. Future review ownership and publication cadence require approval.
Take the next step

Review the evidence, by service.

Request the control records you need or discuss the scope of a security review.

Request applicability evidence → Discuss certification timeline

Document availability and review timing must be confirmed for the request.