Compliance Self-Assessments
AegisGate Security, LLC maintains self-assessment documentation against industry-standard cybersecurity and privacy frameworks. These assessments demonstrate our commitment to transparency and provide customers with visibility into our security posture.
Important: These documents are self-assessments, not third-party certifications. They document how AegisGate’s controls map to each framework’s requirements based on our product architecture, development practices, and operational procedures. Formal third-party audits are planned as the organization scales.
Framework Assessments
| Framework | Scope | Status | Last Reviewed |
|---|---|---|---|
| HIPAA Security Rule | 45 C.F.R. §§ 164.302–318 | Self-Assessment | 2026-07-29 |
| NIST CSF 2.0 | Six core functions (GV, ID, PR, DE, RS, RC) | Self-Assessment | 2026-07-29 |
| SOC 2 Type 1 Readiness | Trust Services Criteria (Security, Availability) | Readiness Assessment | 2026-07-29 |
| CIS Controls v8 IG1 | 56 baseline safeguards | Self-Assessment | 2026-07-29 |
| EU AI Act | Regulation 2024/1689 | Self-Assessment | 2026-07-29 |
ISO 27001 ISMS Documentation
| Document | Scope | Status | Last Reviewed |
|---|---|---|---|
| ISO 27001 Alignment & SoA | All 93 Annex A controls | Alignment Assessment | 2026-07-29 |
| ISMS Policy | Top-level commitment and objectives | Policy | 2026-07-29 |
| Management Review | Quarterly review procedure | Procedure | 2026-07-29 |
| Internal Audit | Annual audit program | Program | 2026-07-29 |
Automated Compliance Engine
AegisGate’s compliance posture is reinforced by our automated compliance engine, which provides continuous enforcement across 27 frameworks:
- 857+ automated CheckFuncs validate controls at runtime
- 153+ detection patterns scan for threats in real time
- 27 compliance frameworks including HIPAA, PCI-DSS, GDPR, SOC 2, FedRAMP, ISO 27001, NIST CSF, CIS, and more
- Hash-chained audit logs provide tamper-evident compliance records
Self-Hosted Architecture Advantage
AegisGate’s self-hosted, on-premises architecture means:
- Customer-controlled infrastructure — AegisGate never sees customer data after deployment
- Customer-managed encryption keys — no backdoor access to encrypted data
- Zero external dependencies — no phone-home, no telemetry, no cloud dependencies
- Customer-managed deployment — Docker container on infrastructure the customer controls
This architectural choice means that many compliance requirements (physical safeguards, data center controls, network segmentation) are the customer’s responsibility. AegisGate provides the software security controls; the customer provides the infrastructure controls.
Review Cycle
Self-assessments are reviewed and updated:
- Quarterly — for material changes in architecture, controls, or regulatory requirements
- Annually — for comprehensive reassessment against updated framework criteria
- Ad hoc — in response to significant security events or customer requirements
Contact
For questions about AegisGate’s compliance posture or to request additional documentation:
AegisGate Security, LLC Email: compliance@aegisgatesecurity.io PGP Key: SECURITY.md