Rigor maintains a SOC 2® Type 2 examination of the RigorOS Platform, performed by an independent auditor, covering the Trust Services Criteria for Security, Availability, and Confidentiality.
We extend that examination into a SOC 2+ model. The same Rigor controls are mapped, where applicable, to the requirements of other frameworks our customers care about: the HIPAA Security Rule, ISO/IEC 27001:2022 Annex A, PCI DSS v4.0.1, and the UK NCSC Cloud Security Principles. In our most recent Type 2, the auditor examined and opined on whether our controls were implemented to meet those additional requirements, not just SOC 2.
This means a single, independently audited control set demonstrates coverage across multiple frameworks at once, so your team can satisfy diverse due-diligence requirements without requesting separate attestations.
Rigor is a CIS SecureSuite® Product Vendor Member.
Visit our Trust Center for the latest on our security posture, audit reports, and compliance documentation.