SOC 2 Type II and ISO 27001 audits are underway. Until they land, OXware ships a built-in compliance scanner that maps every host setting to CIS, NIST 800-53, PCI-DSS, HIPAA, and ISO 27001 controls — and auto-generates auditor-ready PDF reports on demand.
Public progress, real dates, no marketing fog.
Independent auditor engaged. Continuous-monitoring controls live since v2.7.0 (audit log, RBAC, encryption-at-rest, immutable change log).
ISMS scope: oxware.top SaaS components + the OXware Hypervisor product. Stage 1 audit complete; Stage 2 scheduled.
Built into the panel. Maps every host setting to CIS Linux + KVM Hardening Benchmark. Auto-remediation suggestions per finding.
AC, AU, CM, IA, SC, SI control families covered by built-in audit log + RBAC + crypto modules + supply-chain controls.
For workloads handling cardholder data. Scanner flags shared-tenancy violations, weak ciphers, and missing logs.
BAA-ready feature set: at-rest encryption, audit chain, RBAC with break-glass, immutable change log, session recording.
Hit one endpoint, get an auditor-ready PDF. Same report your auditor will accept.
| Control family | Standard | v2.7.2 coverage | How OXware satisfies it |
|---|---|---|---|
| Access control | SOC 2 CC6 / ISO A.9 / 800-53 AC | Pass | RBAC + LDAP/AD + SSO (SAML/OIDC) + 2FA + recovery codes + audit trail. |
| Audit logging | SOC 2 CC7 / 800-53 AU | Pass | SHA-256 hash-chained audit log, immutable JSONL, 90-day retention policy, SIEM export (Splunk, Elastic, Wazuh). |
| Cryptography at rest | HIPAA §164.312(a)(2)(iv) / PCI 3.5 | Pass | LUKS2 on host disks, AES-256-GCM for credential vault, vTPM-sealed keys for confidential VMs. |
| Cryptography in transit | PCI 4.2.1 / 800-53 SC-8 | Pass | TLS 1.3 default, HSTS, secure ciphers only, mTLS for cluster federation. |
| Change management | SOC 2 CC8 / ISO A.12.1.2 | Pass | GitOps manifest sync, immutable change log, plugin AST validation, signed releases. |
| Vendor management | SOC 2 CC9 | Partial | CycloneDX SBOM auto-generated per release; subprocessor list published quarterly. |
| Incident response | 800-53 IR / ISO A.16 | Pass | Auto-remediation runbooks, anomaly detector, alert correlation, on-call rotation via PagerDuty integration. |
| Vulnerability mgmt | PCI 11 / 800-53 RA-5 | Pass | pip-audit + Bandit in CI, bug bounty program, SEC-001..033 tracked, quarterly pen-test rotation. |
Email us for the security questionnaire kit: CAIQ Lite, NIST mapping spreadsheet, SBOM, pen-test summary, sample scanner output. NDA-friendly.
root@oxware.top