Our compliance posture, stated plainly
We believe transparency includes our own credentials. Here is exactly what OSDF aligns with today, what is actively in progress, and what is on the roadmap.
Aligned means the architecture supports the relevant controls. In progress and Roadmap describe work underway or planned. A fully compliant deployment also depends on your environment, policies, and operations.
NIST SP 800-207 (Zero Trust)
Architecture alignment
Maps to Policy Engine, Policy Administrator, and Enforcement Point roles.
FIPS 140-3 validated modules
Cryptographic modules
Validated-module options for regulated deployments.
SOC 2 Type II
Managed services
Controls implementation for hosted platform.
HIPAA technical safeguards
Healthcare deployments
Supports access, audit, integrity, and transmission controls.
ISO/IEC 27001
Information security mgmt
Planned as the organization scales.
FedRAMP
Government cloud
Authorization path under evaluation.
Request our compliance package
We can share current attestations, architecture mappings, and security documentation under NDA.