Skip to content
Trust Center

Search documents, FAQs, frameworks, controls, subprocessors, AI governance and updates.

↑ ↓ to move · Enter to open · Esc to close

Subscribe to updates

Get an email when Safeguard publishes a change here, such as a new report, a policy update or a security incident.

Email me about

By subscribing you agree to the privacy policy (opens in a new tab).

Safeguard

Safeguard is the immune system for software, for both security and compliance. For security, it finds Zero Days across the supply chain and fixes them autonomously, 100 layers deep. For compliance, it automates frameworks such as SOC2, ISO 27001 and GDPR with continuous control monitoring, evidence collection and audit-ready reporting. This page reports our own posture: the frameworks we hold or are working toward, how we handle customer code and data, and how to reach the team that owns it.

Frameworks passing
20/299 in progress · 1 signed
Audited frameworks
2
Documents
44 on request
Subprocessors
9

Live posture

Continuously monitored · last checked
Uptime, 90 days96.72%Measured by our status monitor, currently operational. Status page (opens in a new tab)
Data residencyMulti-regionDefault region: United States. See the hosting footprint
Control monitoringContinuously monitoredSOC2 Trust Services Criteria, last checked 2 hours ago. See controls

Continuous monitoring of our controls against the SOC2 Trust Services Criteria, refreshed from our evidence records. This is live monitoring, not an auditor's opinion.

Data residency: hosting footprint

  • Amazon Web Services

    • Multiple regions
  • Google Cloud

    • Multiple regions
  • Microsoft Azure

    • Multiple regions
  • Oracle Cloud Infrastructure

    • Multiple regions
  • Yotta

    • Mumbai, India
    • GIFT City, India
  • Hetzner

    • Europe

Private cloud, on-premises and air-gapped installations keep customer data in the customer's own environment.

Published by Safeguard.

Compliance

Continuously monitored · last checked checked every 6 hours

ISO 27001:2022

In Progress

ISO 27017:2015

In Progress

SOC2 Type 1

Compliant

Issued by A-LIGN

SOC2 Type 2

Compliant

Issued by A-LIGN

PCI DSS 4.0

Compliant

Secure by Design Pledge

Signed

FedRAMP Rev. 5

In Progress

ISO 27018:2019

In Progress

ISO 27701:2019

In Progress

ISO/IEC 42001:2023

In Progress

GDPR

Compliant

CCPA / CPRA

Compliant

India DPDP Act 2023

Compliant

CERT-In Directions (India)

Compliant

HIPAA

Compliant

NIST CSF 2.0

Compliant

NIST SP 800-53 Rev. 5

Compliant

NIST SSDF (SP 800-218)

Compliant

SLSA Build L3

Compliant

EU AI Act

Compliant

NIST AI RMF 1.0

Compliant

EU Cyber Resilience Act

Compliant

CSA STAR Level 1

Compliant

CMMC 2.0

In Progress

NIST SP 800-171

Compliant

StateRAMP

In Progress

UK GDPR / DPA 2018

Compliant

STQC (India)

In Progress

EU NIS2 Directive

Compliant

EU DORA

Compliant

EU emblem: European Union. It marks legislation of the European Union and does not mean the EU is connected with this organisation. NIST CSF 2.0 graphic reprinted courtesy of the National Institute of Standards and Technology, U.S. Department of Commerce. NIST SSDF logo: NIST. SLSA logo: The Linux Foundation, linking to slsa.dev. NIST AI RMF graphic: N. Hanacek/NIST.

Current status for each framework. Where a certification is held, the certificate and its scope are available on request.

Resources

View all
Penetration testing1 on request1
Compliance2 on request2
Security1 on request1

Controls

View all

People and HR

2 monitored
  • Commitment to competence: personnel acknowledge security policies
  • Security responsibilities communicated internally

Access controls

3 monitored
  • Logical access security, credentials and encryption keys
  • User provisioning and deprovisioning
  • Access modification and periodic review

5 further control areas on the Controls page.

Subprocessors

View all
Amazon Web Services

Amazon Web Services (opens in a new tab)

Cloud hosting and infrastructure

Multi-region
Google Cloud

Google Cloud (opens in a new tab)

Cloud hosting and infrastructure

Multi-region
Microsoft Azure

Microsoft Azure (opens in a new tab)

Cloud hosting and infrastructure

Multi-region
Oracle Cloud Infrastructure

Oracle Cloud Infrastructure (opens in a new tab)

Cloud hosting and infrastructure

Multi-region
Where is Safeguard hosted?

Safeguard SaaS runs in multiple regions on Amazon Web Services, Google Cloud, Microsoft Azure and Oracle Cloud Infrastructure, on Yotta in India (Mumbai and GIFT City) and on Hetzner in Europe. Private cloud, on-prem and air-gapped deployments run entirely in your own environment.

How can we deploy or buy Safeguard?

As multi-region SaaS; as Safeguard for Government for public-sector customers; or installed in your own private cloud, on-prem or fully air-gapped. You can buy directly, through AWS Marketplace, or by private offer.

Do self-hosted deployments send data to third parties?

No. Private cloud, on-prem and air-gapped installs run entirely in your environment, including Safeguard's own AI models, so no third-party subprocessor receives your data. Third-party AI models or scanners are used only if you choose to connect them. The subprocessors listed on this page apply to the SaaS offering.

Can we buy Safeguard through our cloud marketplace?

On AWS Marketplace, yes: listings are public and a purchase can draw down your committed AWS spend, including by private offer. Our Microsoft Marketplace listings are live for discovery and provisioning but are not yet transactable. Google Cloud Marketplace is in review, and an Oracle Cloud Marketplace listing is in progress; until they are live, buy directly or by private offer.

Updates

Subprocessor list published

General

4 Oct 2026

Our Trust Center now lists every subprocessor used by the Safeguard SaaS offering, with its purpose and location. Private cloud, on-prem and air-gapped deployments use none of them.

Request access to restricted documents

Compliance

4 Oct 2026

You can now request access to restricted documents, such as audit reports, directly from this Trust Center. Each request is verified by email, covered by an NDA and approved by our team.

Request access

Loading…

Safeguard Trust Center