● Trust Center

Security & compliance you can verify — not just trust.

Cyber Nerve Center treats compliance as machine-readable data. Our security posture is summarized below, and our full compliance artifacts — SBOM, SSP, SAR, and POA&M — are available as machine-readable OSCAL under a mutual NDA.

The 2029 thesis

By 2029, businesses won't exchange PDF security questionnaires — they'll share machine-readable SBOMs, System Security Plans, Security Assessment Results, and POA&Ms and let software decide, in seconds, whether two organizations are safe to work together. Cyber Nerve Center is built to produce and exchange exactly those artifacts. This Trust Center is that future, working today.

Compliance posture

🔎 Full transparency: Cyber Nerve Center is an early-stage company and does not currently hold any third-party security certifications. The items below reflect the open standards our program is built to and our certification roadmap — not attestations. Rather than ask you to take our word for it, we share machine-readable artifacts (below) so you can verify our controls directly.

In place implemented in our program today  ·  Roadmap a future goal, not yet started or certified.

🧬

OSCAL-native program In place

Controls, evidence, and assessment artifacts maintained as machine-readable OSCAL (NIST 1.1.x).

📗

Built to NIST SP 800-53 Rev 5 In place

Control baseline modeled and mapped as our source of truth (self-assessed, not certified).

🛡️

Built to NIST CSF 2.0 In place

Program organized across Govern → Recover (self-assessed).

🔏

SOC 2 Type II Roadmap

Not yet pursued. Our continuous-monitoring architecture is designed to support it when we do.

📄

ISO/IEC 27001 & 42001 Roadmap

Information-security and AI-management certifications are future goals.

🏛️

FedRAMP 20x Roadmap

Architected for machine-readable authorization (RFC-0024); a target as we enter federal markets.

How we protect data

The controls behind the posture — the same architecture our product is built on.

🔐

Per-tenant encryption

Each customer's data is encrypted at rest with a dedicated customer-managed key (CMEK), across database, evidence storage, and backups. Encrypted in transit (TLS).

🧱

Tenant isolation

Every customer runs in a dedicated, network-fenced graph database — no shared multi-tenant store. Crypto-shred on offboarding.

🪪

Identity & access

Least-privilege access, phishing-resistant MFA, and risk-based assurance aligned to NIST SP 800-63-4.

♻️

Resilience & backup

Cross-zone replicated storage (zero-RPO for zone loss) plus managed daily backups with tested restore.

🧾

Audit & traceability

Immutable audit ledger of security-relevant changes; versioned, retained evidence for point-in-time history.

🤖

Governed AI

AI features are grounded, human-in-the-loop, and governed to the NIST AI RMF and ISO/IEC 42001.

Documents available under NDA

Our compliance artifacts are shared as machine-readable OSCAL (and standard SBOM formats) so your team — or your tooling — can evaluate us programmatically. Available after a mutual NDA is executed.

Software Bill of MaterialsSPDX / CycloneDXFull dependency inventory for supply-chain review.Available
System Security Plan (SSP)OSCAL JSONHow each control is implemented across the platform.Available
Security Assessment Results (SAR)OSCAL JSONFindings and observations from control assessment.On request
Plan of Action & Milestones (POA&M)OSCAL JSONOpen items with owners and remediation timelines.Available
Component DefinitionsOSCAL JSONControl implementation per infrastructure component.Available
Security policiesPDFGovernance, access, incident response, and more.Available
Penetration test summaryPDFIndependent assessment summary.Planned
📎 How it works: request access below → we send a mutual NDA for signature → on execution, you receive a secure link to the machine-readable artifacts. Machine-readable formats mean your GRC tooling can ingest and evaluate them directly — no manual questionnaire.

Subprocessors

Third parties that may process data on our behalf, under contractual data-protection obligations.

Google Cloud Platform

Infrastructure, hosting, storage, and key management (United States).

AI model providers

Governed AI inference (e.g., Google Vertex AI / Anthropic) — customer content is not used to train third-party foundation models.

Request document access

Tell us who you are and what you'd like to review. We'll respond with a mutual NDA; documents follow on signature.

I understand documents are shared only after a mutual NDA is executed, and I'm authorized to enter one on behalf of my company.