generated: '2026-08-26' method: searched probe: true url: https://trust.regscale.com/ source: https://regscale.com/security/ note: >- RegScale runs a dedicated trust center at trust.regscale.com (HTTP 200, title "Trust Center - Compliance Management Platform"). It is a single-page application that renders its content client-side, so the automated keyword probe found nothing in the served HTML - the certifications recorded below were read from RegScale's own public security page, which states each one with a date and an issuing context. That SPA behaviour is also why every /.well-known/* path on that host answers 200 with the same shell (see well-known/regscale-well-known.yml). certifications: - FedRAMP High - SOC 2 Type 2 - ISO 27001:2022 - TX-RAMP Level 2 - CSA STAR Level 1 - CSA STAR Valid-AI-ted - 'DoD IL5 (in process)' - HIPAA - GDPR detail: fedramp_high: authorized: '2025-06' sponsor: DHS marketplace: true soc2_type2: achieved: '2024-01' availability: upon request iso_27001: version: '2022' controls: 123 nonconformities: 0 auditor: A-LIGN tx_ramp: level: 2 baseline: NIST SP 800-53 Moderate csa_star: level_1: '2024-08' valid_ai_ted: '2025-09' caiq_score: '97.7%' dod_il5: status: in-process sbom: published: on-request scope: - Core RegScale Application - RegScale CLI Automation Platform format: not stated evidence: - source: https://trust.regscale.com/ http_status: 200 content_type: text/html note: SPA shell; certifications not present in server-rendered HTML - source: https://regscale.com/security/ http_status: 200 keywords: [soc 2 type 2, fedramp high, iso 27001, tx-ramp, csa star, dod il5, sbom]