Compliance Self-Assessments

AegisGate Security Platform compliance self-assessments documenting our security posture against industry frameworks.

Compliance Self-Assessments

AegisGate Security, LLC maintains self-assessment documentation against industry-standard cybersecurity and privacy frameworks. These assessments demonstrate our commitment to transparency and provide customers with visibility into our security posture.

Important: These documents are self-assessments, not third-party certifications. They document how AegisGate’s controls map to each framework’s requirements based on our product architecture, development practices, and operational procedures. Formal third-party audits are planned as the organization scales.


Framework Assessments

FrameworkScopeStatusLast Reviewed
HIPAA Security Rule45 C.F.R. §§ 164.302–318Self-Assessment2026-07-29
NIST CSF 2.0Six core functions (GV, ID, PR, DE, RS, RC)Self-Assessment2026-07-29
SOC 2 Type 1 ReadinessTrust Services Criteria (Security, Availability)Readiness Assessment2026-07-29
CIS Controls v8 IG156 baseline safeguardsSelf-Assessment2026-07-29
EU AI ActRegulation 2024/1689Self-Assessment2026-07-29

ISO 27001 ISMS Documentation

DocumentScopeStatusLast Reviewed
ISO 27001 Alignment & SoAAll 93 Annex A controlsAlignment Assessment2026-07-29
ISMS PolicyTop-level commitment and objectivesPolicy2026-07-29
Management ReviewQuarterly review procedureProcedure2026-07-29
Internal AuditAnnual audit programProgram2026-07-29

Automated Compliance Engine

AegisGate’s compliance posture is reinforced by our automated compliance engine, which provides continuous enforcement across 27 frameworks:

  • 857+ automated CheckFuncs validate controls at runtime
  • 153+ detection patterns scan for threats in real time
  • 27 compliance frameworks including HIPAA, PCI-DSS, GDPR, SOC 2, FedRAMP, ISO 27001, NIST CSF, CIS, and more
  • Hash-chained audit logs provide tamper-evident compliance records

Self-Hosted Architecture Advantage

AegisGate’s self-hosted, on-premises architecture means:

  • Customer-controlled infrastructure — AegisGate never sees customer data after deployment
  • Customer-managed encryption keys — no backdoor access to encrypted data
  • Zero external dependencies — no phone-home, no telemetry, no cloud dependencies
  • Customer-managed deployment — Docker container on infrastructure the customer controls

This architectural choice means that many compliance requirements (physical safeguards, data center controls, network segmentation) are the customer’s responsibility. AegisGate provides the software security controls; the customer provides the infrastructure controls.


Review Cycle

Self-assessments are reviewed and updated:

  • Quarterly — for material changes in architecture, controls, or regulatory requirements
  • Annually — for comprehensive reassessment against updated framework criteria
  • Ad hoc — in response to significant security events or customer requirements

Contact

For questions about AegisGate’s compliance posture or to request additional documentation:

AegisGate Security, LLC Email: compliance@aegisgatesecurity.io PGP Key: SECURITY.md