generated: '2026-09-05' method: probed source: >- probe-security-programs.py 2026-09-05 (vdp=none trust=none) plus manual review of https://buildpacks.io/, https://buildpacks.io/community/, https://buildpacks.io/history and https://github.com/buildpacks/.github/blob/main/SECURITY.md provider: Cloud Native Buildpacks providerId: buildpacks published: false description: >- Cloud Native Buildpacks operates no trust center and holds no SOC 2, ISO 27001, PCI, HIPAA or FedRAMP certification — and that is the correct posture, not a gap. CNB is a self-hosted open-source specification project: it processes no customer data and operates no multi-tenant service that could be in scope for those audits. The only hosted surface is a read-only public index at registry.buildpacks.io. What it publishes instead is open-source assurance: a completed third-party security audit, an OpenSSF Best Practices badge, a CNCF security self-assessment, and CNCF Graduated status — recorded in security/buildpacks-vulnerability-disclosure.yml and conformance/buildpacks-conformance.yml. certifications: [] trust_center_url: null assurance_artifacts: - name: Third-party security audit (Quarkslab / OSTIF, CNCF-funded) date: '2024-07-17' url: https://ostif.org/buildpacks-audit-complete/ - name: OpenSSF Best Practices badge url: https://bestpractices.coreinfrastructure.org/projects/4748 - name: CNCF security self-assessment date: '2021-09-07' - name: CNCF Graduated status date: '2026-08-11' url: https://buildpacks.io/history#graduation