Trust Center

Everything your security team asks for, in one place.

The whitepaper, a self-serve security questionnaire, our pen-test methodology, service-level commitments, live status, and every legal document — with honest status on every certification, never a claim we can't back.

02 · Certification status

Honest about where we are.

We will say a framework is certified only once an independent auditor has signed off — and we will link the report here when that happens. Until then, this is exactly where we stand.

SOC 2
In progress — no certificate held
ISO 27001
Control mappings — not certified
Third-party pen test
Scoped & scheduled — no attestation yet
Independent trusted timestamping
Not used — signatures are Ed25519 + Merkle

Separately, the product helps your team produce auditor-ready evidence mapped across seven frameworks — exported as NIST OSCAL and verifiable offline. That is a TrustFix feature for your compliance program; it is not a claim about TrustFix’s own certification status. Read the boundary in the whitepaper’s §8.

03 · Legal & trust documents

Operated by Vikavi Security LLC, a Delaware LLC · Greater St. Louis, USA · security@trustfix.dev

Trust Center | TrustFix