Compliance Self-Assessments

AegisGate Security Platform compliance self-assessments documenting our security posture against industry frameworks. Listed in the CSA STAR Registry and Startup Showcase.

Compliance Self-Assessments

AegisGate Security, LLC maintains self-assessment documentation against industry-standard cybersecurity and privacy frameworks. These assessments demonstrate our commitment to transparency and provide customers with visibility into our security posture.

Important: These documents are self-assessments, not third-party certifications. They document how AegisGate’s controls map to each framework’s requirements based on our product architecture, development practices, and operational procedures. Formal third-party audits are planned as the organization scales.


CSA STAR Registry

AegisGate Security is listed in the Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) Registry at Level 1. Our AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) self-assessment — 311 questions documenting our compliance with the AI Controls Matrix (AICM) — is publicly available.

View our STAR Registry listing →

  • Listed since: 2026-09-17
  • Assessment: AI-CAIQ v1.0.2 (311 questions, 184 Yes / 127 NA)
  • Level: STAR Level 1 (Self-Assessment)

CSA Startup Showcase

AegisGate Security is featured in the CSA Startup Showcase, highlighting our solution for Agentic AI Identity and Access Management.

View our Startup Showcase listing →


Framework Assessments

FrameworkScopeStatusLast Reviewed
HIPAA Security Rule45 C.F.R. §§ 164.302–318Self-Assessment2026-07-29
NIST CSF 2.0Six core functions (GV, ID, PR, DE, RS, RC)Self-Assessment2026-07-29
SOC 2 Type 1 ReadinessTrust Services Criteria (Security, Availability)Readiness Assessment2026-07-29
CIS Controls v8 IG156 baseline safeguardsSelf-Assessment2026-07-29
EU AI ActRegulation 2024/1689Self-Assessment2026-07-29

ISO 27001 ISMS Documentation

DocumentScopeStatusLast Reviewed
ISO 27001 Alignment & SoAAll 93 Annex A controlsAlignment Assessment2026-07-29
ISMS PolicyTop-level commitment and objectivesPolicy2026-07-29
Management ReviewQuarterly review procedureProcedure2026-07-29
Internal AuditAnnual audit programProgram2026-07-29

Automated Compliance Engine

AegisGate’s compliance posture is reinforced by our automated compliance engine, which provides continuous enforcement across 31 frameworks:

  • 1,457 automated controls validate controls at runtime
  • 216 detection patterns scan for threats in real time
  • 31 compliance frameworks including HIPAA, PCI-DSS, GDPR, SOC 2, FedRAMP, ISO 27001, NIST CSF, CIS, and more
  • Hash-chained audit logs provide tamper-evident compliance records

Self-Hosted Architecture Advantage

AegisGate’s self-hosted, on-premises architecture means:

  • Customer-controlled infrastructure — AegisGate never sees customer data after deployment
  • Customer-managed encryption keys — no backdoor access to encrypted data
  • Zero external dependencies — no phone-home, no telemetry, no cloud dependencies
  • Customer-managed deployment — Docker container on infrastructure the customer controls

This architectural choice means that many compliance requirements (physical safeguards, data center controls, network segmentation) are the customer’s responsibility. AegisGate provides the software security controls; the customer provides the infrastructure controls.


Review Cycle

Self-assessments are reviewed and updated:

  • Quarterly — for material changes in architecture, controls, or regulatory requirements
  • Annually — for comprehensive reassessment against updated framework criteria
  • Ad hoc — in response to significant security events or customer requirements

Contact

For questions about AegisGate’s compliance posture or to request additional documentation:

AegisGate Security, LLC Email: compliance@aegisgatesecurity.io PGP Key: SECURITY.md