generated: '2026-08-02' method: searched source: https://www.aidash.com/security-compliance-and-responsible-ai/ scope: 'Organizational / cross-cutting standards only. AiDASH publishes no machine-readable API contract (no OpenAPI, AsyncAPI, GraphQL SDL, or MCP manifest was found on any reachable host), so no protocol-level conformance can be derived from a spec. Every entry below is evidenced by a published AiDASH or third-party page.' standards: - id: soc2-type2 name: SOC 2 Type 2 conforms: true evidence: 'AiDASH states it received SOC 2 Type 2 certification with no exceptions for the fifth consecutive year; listed as "SOC 2 Compliant" on its Sprinto trust center.' url: https://security.aidash.com/ - id: soc3 name: SOC 3 conforms: true evidence: Public SOC 3 report published on aidash.com (2026 edition). url: https://www.aidash.com/wp-content/uploads/2026/05/AiDASH-Inc.-SOC-3-2026.pdf - id: csa-star-level-1 name: CSA STAR Level 1 (CAIQ self-assessment) conforms: true evidence: Cloud Security Alliance STAR Registry entry, listed since 2021-02-09. url: https://cloudsecurityalliance.org/star/registry/aidash/ - id: iso-27001 name: ISO/IEC 27001 conforms: false evidence: No ISO 27001 certification named on the trust center, the security and compliance page, or the CSA STAR entry. - id: iso-27701 name: ISO/IEC 27701 conforms: false evidence: Not named on any published AiDASH security page. - id: pci-dss name: PCI DSS conforms: false evidence: Not applicable / not claimed — AiDASH does not process cardholder data as part of its platform. - id: hipaa name: HIPAA conforms: false evidence: Not claimed; AiDASH serves utilities, water companies, and landowners, not healthcare. - id: fedramp name: FedRAMP conforms: false evidence: No FedRAMP authorization named on the trust center or in the FedRAMP marketplace search. - id: oauth2 name: OAuth 2.0 conforms: unknown evidence: 'No public OAuth metadata — /.well-known/oauth-authorization-server and /.well-known/openid-configuration returned 404 on every reachable host. The customer platform is behind an authenticated SPA, so the auth model could not be observed anonymously.' - id: openid-connect name: OpenID Connect conforms: unknown evidence: /.well-known/openid-configuration returned 404 on www, iris, and connect hosts. - id: rfc9457-problem-details name: RFC 9457 Problem Details conforms: unknown evidence: No OpenAPI or error reference published; error envelope could not be observed. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returned 404 on all probed hosts (see well-known/aidash-well-known.yml). - id: a2a-agent-card name: A2A Agent Card conforms: false evidence: Neither /.well-known/agent-card.json nor /.well-known/agent.json resolved on any host. gaps: - 'No public developer portal, API reference, or getting-started guide — AiDASH markets "secure, full REST APIs" and "industry-standard connectors" on its platform page, but the contract is customer-gated behind commercial engagement.' - No status page, changelog, deprecation policy, or SLA published. - No published vulnerability-disclosure contact or bug-bounty program; the Vulnerability Management Policy on the trust center is access-gated. - No HSTS on www.aidash.com, no DNSSEC, no CAA records; DMARC policy is `quarantine` rather than `reject` (see security/aidash-domain-security.yml).