1"use strict";(self.webpackChunkspectro_cloud_docs=self.webpackChunkspectro_cloud_docs||[]).push([["14000"],{600054:function(e,t,i){i.r(t),i.d(t,{frontMatter:()=>o,toc:()=>l,default:()=>p,metadata:()=>n,assets:()=>c,contentTitle:()=>r});var n=JSON.parse('{"id":"legal-licenses/compliance","title":"Certification of Compliance","description":"Certification of Compliance","source":"@site/docs/docs-content/legal-licenses/compliance.md","sourceDirName":"legal-licenses","slug":"/legal-licenses/compliance","permalink":"/legal-licenses/compliance","draft":false,"unlisted":false,"editUrl":"https://github.com/spectrocloud/librarium/blob/master/docs/docs-content/legal-licenses/compliance.md","tags":[{"inline":true,"label":"compliance","permalink":"/tags/compliance"},{"inline":true,"label":"soc2","permalink":"/tags/soc-2"},{"inline":true,"label":"fips","permalink":"/tags/fips"}],"version":"current","lastUpdatedAt":1777826507000,"sidebarPosition":0,"frontMatter":{"sidebar_label":"Compliance","title":"Certification of Compliance","description":"Certification of Compliance","hide_table_of_contents":false,"sidebar_position":0,"tags":["compliance","soc2","fips"]},"sidebar":"docSidebar","previous":{"title":"Compliance & Legal","permalink":"/legal-licenses/"},"next":{"title":"Open Source Licenses","permalink":"/legal-licenses/oss-licenses-index/"}}'),s=i(474848),a=i(884429);let o={sidebar_label:"Compliance",title:"Certification of Compliance",description:"Certification of Compliance",hide_table_of_contents:!1,sidebar_position:0,tags:["compliance","soc2","fips"]},r,c={},l=[{value:"ISO 27001:2022",id:"iso-270012022",level:2},{value:"SOC 2 Type II",id:"soc-2-type-ii",level:2},{value:"FIPS 140-3",id:"fips-140-3",level:2},{value:"Joint Certification Program",id:"joint-certification-program",level:2},{value:"UK Cyber Essentials Plus Certification",id:"uk-cyber-essentials-plus-certification",level:2},{value:"UK Cyber Essentials Certification",id:"uk-cyber-essentials-certification",level:2}];function d(e){let t={a:"a",h2:"h2",img:"img",li:"li",p:"p",strong:"strong",ul:"ul",...(0,a.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(t.h2,{id:"iso-270012022",children:"ISO 27001:2022"}),"\n",(0,s.jsx)(t.p,{children:(0,s.jsx)(t.img,{alt:"ISO 27001 logo",src:i(969364).A+"",title:"#width=300px",width:"500",height:"500"})}),"\n",(0,s.jsx)(t.p,{children:"The International Organization for Standardization 27001 Standard (ISO 27001) is one of the leading international\nstandards focused on information security. Spectro Cloud has obtained the ISO 27001:2022 Certification and undergoes\nperiodic audits to maintain this certification. ISO 27001:2022 Certification provides assurances that Spectro Cloud is\nidentifying and managing risks effectively, consistently, and measurably."}),"\n",(0,s.jsx)(t.p,{children:"Below are some reasons why an ISO 27001:2022 Certification is important:"}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsxs)(t.li,{children:["\n",(0,s.jsxs)(t.p,{children:[(0,s.jsx)(t.strong,{children:"Customer trust and confidence"}),": Clients and partners often look for assurances that their sensitive information is\nhandled securely. Achieving ISO 27001:2022 certification can enhance customer trust and confidence, potentially\nleading to increased business opportunities."]}),"\n"]}),"\n",(0,s.jsxs)(t.li,{children:["\n",(0,s.jsxs)(t.p,{children:[(0,s.jsx)(t.strong,{children:"Risk Management"}),": By implementing ISO controls and measures, companies can mitigate these risks, protecting\nsensitive data from unauthorized access or disclosure."]}),"\n"]}),"\n",(0,s.jsxs)(t.li,{children:["\n",(0,s.jsxs)(t.p,{children:[(0,s.jsx)(t.strong,{children:"Legal and regulatory compliance"}),": Adhering to ISO 27001:2022 demonstrates a commitment to information security,\nwhich can help organizations comply with various legal and regulatory requirements related to data protection and\nprivacy."]}),"\n"]}),"\n",(0,s.jsxs)(t.li,{children:["\n",(0,s.jsxs)(t.p,{children:[(0,s.jsx)(t.strong,{children:"Global recognition"}),": ISO 27001:2022 is globally recognized. This helps organizations communicate their commitment\nto information security across borders."]}),"\n"]}),"\n"]}),"\n",(0,s.jsx)(t.h2,{id:"soc-2-type-ii",children:"SOC 2 Type II"}),"\n",(0,s.jsx)(t.p,{children:(0,s.jsx)(t.img,{alt:"soc2.webp",src:i(981830).A+"",title:"#width=180px",width:"862",height:"880"})}),"\n",(0,s.jsx)(t.p,{children:"The American Institute of Certified Public Accountants (AICPA) Service Organization Controls (SOC) Attestation provides\nassurances over control environments. Spectro Cloud\u2019s SOC 2 Type II audit report provides assurances of our\norganization\u2019s security and availability."}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsxs)(t.li,{children:["\n",(0,s.jsx)(t.p,{children:"SOC 2 audits are an important component in regulatory oversight, vendor management programs, internal governance, and\nrisk management."}),"\n"]}),"\n",(0,s.jsxs)(t.li,{children:["\n",(0,s.jsx)(t.p,{children:"These reports help our users and their auditors understand the controls established at Spectro Cloud to support\noperations and compliance."}),"\n"]}),"\n",(0,s.jsxs)(t.li,{children:["\n",(0,s.jsx)(t.p,{children:"Spectro Cloud\u2019s SOC 2 Type II report is available upon request for any customers or prospects with a signed\nnon-disclosure agreement in place."}),"\n"]}),"\n"]}),"\n",(0,s.jsx)(t.h2,{id:"fips-140-3",children:"FIPS 140-3"}),"\n",(0,s.jsxs)(t.p,{children:["Spectro Cloud is validated against FIPS 140-3 with\n",(0,s.jsx)(t.a,{href:"https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5061",children:"Certificate number 5061"})," in\ncompliance with the Cryptographic Module Validation Program (CMVP)."]}),"\n",(0,s.jsxs)(t.p,{children:["Our Spectro Cloud Cryptographic Module is a general-purpose cryptographic library. The FIPS-enforced Palette VerteX\nedition incorporates the module in the Kubernetes Management Platform and the infrastru
1cture components of target\nclusters to protect the sensitive information of regulated industries. Palette VerteX supports FIPS at the tenant level.\nFor more information about the FIPS-enforced Palette edition, check out ",(0,s.jsx)(t.a,{href:"/vertex/",children:"Palette VerteX"}),"."]}),"\n",(0,s.jsx)(t.h2,{id:"joint-certification-program",children:"Joint Certification Program"}),"\n",(0,s.jsx)(t.p,{children:(0,s.jsx)(t.img,{alt:"JPC-Compliance",src:i(387474).A+"",title:"#width=687px",width:"687",height:"87"})}),"\n",(0,s.jsx)(t.p,{children:"We maintain certification under the Joint Certification Program, a program between Canada\u2019s Department of National\nDefense and the U.S. Department of Defense, that helps to protect controlled Unclassified Military Critical Technical\nData (MCTD) and technology from common adversaries. Our Joint Certification Program certification establishes the\neligibility of Spectro Cloud, Inc., to receive technical data governed by the Technical Data Control Regulations (TCDR)."}),"\n",(0,s.jsx)(t.h2,{id:"uk-cyber-essentials-plus-certification",children:"UK Cyber Essentials Plus Certification"}),"\n",(0,s.jsx)("div",{style:{display:"flex",justifyContent:"center"},children:(0,s.jsx)("iframe",{src:"https://registry.blockmarktech.com/certificates/41827ab6-48ed-4a59-8061-2792659a5802/widget/?tooltip_position=bottom&theme=transparent",style:{border:"none",height:180,width:180},title:"Blockmark certificate widget",loading:"lazy"})}),"\n",(0,s.jsx)(t.p,{children:"Spectro Cloud is proud to be UK Cyber Essentials Plus certified, the advanced level of the UK Government-backed Cyber\nEssentials cybersecurity standard. Cyber Essentials is a scheme developed by the UK\u2019s National Cyber Security Centre\n(NCSC) to help organizations of all sizes guard against the most common internet-based cyber threats by implementing a\ndefined set of technical security controls. Cyber Essentials Plus includes independent, hands-on technical testing of\nour systems, conducted by accredited specialists to verify that our defenses are effectively implemented and operating\nas intended. This certification demonstrates our commitment to strong cyber hygiene, validated security practices, and\ntrustworthy operations for customers, partners, and supply chains that demand high assurance against everyday cyber\nrisks."}),"\n",(0,s.jsx)(t.h2,{id:"uk-cyber-essentials-certification",children:"UK Cyber Essentials Certification"}),"\n",(0,s.jsx)("div",{style:{display:"flex",justifyContent:"center"},children:(0,s.jsx)("iframe",{src:"https://registry.blockmarktech.com/certificates/2f98929e-e319-4056-86f9-aac8657b930b/widget/?tooltip_position=bottom&theme=transparent",style:{border:"none",height:180,width:180},title:"Blockmark certificate widget",loading:"lazy"})}),"\n",(0,s.jsx)(t.p,{children:"Spectro Cloud\u2019s achievement of the UK Cyber Essentials certification underscores our commitment to maintaining the\nhighest standards of cybersecurity and data protection. This government-backed accreditation establishes a baseline\nlevel of security that all organizations should have in place to defend against the most common types of cyberattacks,\nincluding phishing, malware, and hacking attempts that exploit poor configurations or weak passwords."})]})}function p(e={}){let{wrapper:t}={...(0,a.R)(),...e.components};return t?(0,s.jsx)(t,{...e,children:(0,s.jsx)(d,{...e})}):d(e)}},387474:function(e,t,i){i.d(t,{A:()=>n});let n=i.p+"assets/images/docs_compliance_compliance_jpc-logo-4a246a9e16d796c7f2af319bf811534a.webp"},969364:function(e,t,i){i.d(t,{A:()=>n});let n=i.p+"assets/images/legal-licenses_compliance_iso-27001-eedbe0d048f0b79a296de5b452387399.webp"},981830:function(e,t,i){i.d(t,{A:()=>n});let n=i.p+"assets/images/soc2-c8332cb07c98cdf0dfcdca5107315236.webp"},884429:function(e,t,i){i.d(t,{R:()=>o,x:()=>r});var n=i(296540);let s={},a=n.createContext(s);function o(e){let t=n.useContext(a);return n.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function r(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:o(e.components),n.createElement(a.Provider,{value:t},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.