generated: '2026-08-17' method: searched probe: true url: https://docs.rainbowstandard.io/other/administrative-oversight note: >- There is no trust.rainbowstandard.io and no vendor-style trust portal (NXDOMAIN — probed). What Rainbow (formerly Riverse) publishes instead is an Administrative Oversight Record: a dated, linked archive of Standard Advisory Board meeting decisions, Annual Activity Reports, a mission audit statement, and — the part that matters for a registry — its twice-yearly Registry Internal IT Audit reports, most recently 2026-07-20. The Procedures Manual commits to that cadence in writing ("at least twice per calendar year ... summarize the findings in a report made publicly available"), and the record shows the commitment being met. That is the trust surface, and it is why the TrustCenter pointer is emitted. certifications: note: >- These are carbon-programme accreditations, NOT information-security certifications. Rainbow publishes no SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP attestation of its own, and none should be inferred from this file. programme: - {name: ICVCM Core Carbon Principles (CCP-Eligible), date: '2026-03', url: 'https://rainbowstandard.io/news/rainbow-officially-approved-by-the-icvcm'} - {name: ICROA full endorsement, url: 'https://rainbowstandard.io/news/rainbow-receives-full-endorsement-from-icroa'} - {name: Frontier — approved credit issuer, date: '2026-05', url: 'https://rainbowstandard.io/news/frontier-approves-rainbow-as-a-credit-issuer'} - {name: EU CRCF (EU/2024/3012) compliant crediting track, url: 'https://docs.rainbowstandard.io/rainbow-standard-documents/procedures-manual/crcf-requirements'} information_security: [] audits: cadence_commitment: >- "The Rainbow Secretariat shall verify at least twice per calendar year that the IT security requirements are met, and summarize the findings in a report made publicly available on the Rainbow documentation hub." published: - {date: '2026-07-20', type: Registry Internal IT Audit} - {date: '2026-01-20', type: Registry Internal IT Audit} - {date: '2025-07-28', type: Registry Internal IT Audit} - {date: '2024-05-15', type: Mission audit statement} checklist: - Verify compliance with the published minimum security requirements - Verify security vulnerability status and upgrade all JavaScript dependencies with npm - Review authentication provider access - Review cloud provider IAM accounts and access - Rotate database passwords and API keys (internal and external) - Review database connection allowlist - Review repository history for leaked secrets - Verify application authorization rules governance: url: https://docs.rainbowstandard.io/other/governance-and-integrity bodies: [Governing Board, Standard Advisory Board (SAB), Expert Community, Secretariat] sab_meeting_records_published: 6 annual_activity_reports_published: 3 complaints_and_sanctions: No complaints have been received, or sanctions applied. policies: - Conflict of Interest Policy - Complaints and Appeals Policy - KYC Policy - Anti-Bribery and Corruption Policy - Anti-Money Laundering (AML) Policy - Corporate Social & Environmental Responsibility (CSR) Policy - Privacy policy - Cookie Policy evidence: - {source: 'https://docs.rainbowstandard.io/other/administrative-oversight.md', status: 200, keywords: [IT audit, oversight, annual activity report, mission audit]} - {source: 'https://docs.rainbowstandard.io/other/governance-and-integrity', status: 200, keywords: [governance, KYC, AML, anti-bribery, conflict of interest]} - {source: 'https://trust.rainbowstandard.io/', status: 0, note: NXDOMAIN} - {source: 'https://docs.rainbowstandard.io/rainbow-standard-documents/procedures-manual/registry-requirements.md', status: 200, keywords: [registry IT security, security audit, incident procedures]}