Home Trust portal

Trust portal

Compliance certifications, SBOMs, pen-test summaries, and EU CRA Annex IV documentation.

Last updated: May 24, 2026
Security & disclosure

Report a vulnerability

sapctl runs a Coordinated Vulnerability Disclosure (CVD) program. Report privately via our security policy or email [email protected]. We acknowledge within 72 hours and credit reporters who follow CVD.

Certifications & attestations

SOC 2 Type I

Trust Services Criteria · audit window in progress

Type I attestation (controls design) is in its audit window with an AICPA-licensed firm. Type II (operating effectiveness) follows after the observation period. Draft control narratives available under NDA.

ISO/IEC 27001:2022

Information security management · roadmap

Targeted scope: design, development, and operation of sapctl cloud services. Certification is planned to follow the SOC 2 audit; ISMS controls are being implemented in parallel.

PCI DSS

Not in scope

Cardholder data is processed by Stripe; sapctl never stores PAN. SAQ-A applies to our merchant relationship.

Software bill of materials

Every signed release publishes a CycloneDX 1.7 and SPDX 3.0.1 SBOM, plus SLSA L3 provenance attestations and a cosign signature. The list below is pulled live from the latest GitHub release:

Loading latest release evidence…

Verify with cosign verify-blob against our public Fulcio identity. Every signature is logged in the public Rekor transparency log.

Penetration testing

Annual third-party penetration test, with a retest after material architecture change. Executive summary available on request; the full report is available under NDA.

Regulatory mapping

sapctl does not make you compliant — it gives you the evidence primitives auditors ask for. Each regulation below maps to a concrete command or artefact.

EU CRA

Cyber Resilience Act

SBOM (CycloneDX 1.7), SLSA L3 provenance, and a CVD policy on every release feed Annex IV technical documentation and the vulnerability-handling requirement.

EU DORA

Digital Operational Resilience Act

The ed25519 hash-chained audit log gives tamper-evident records of every SAP API call for ICT-risk reporting; the air-gap bundle format supports resilience testing on isolated networks.

sapctl audit verify
SOX 404

Sarbanes-Oxley, ITGC

Signed journal extracts (--use-case sox-journal) produce an auditor-verifiable evidence chain for financial-reporting controls, independent of SAP GUI screenshots.

sapctl s4 audit-export
21 CFR Part 11

FDA electronic records

The hash-chained log provides the audit trail, record integrity, and signature linkage Part 11 requires for regulated life-sciences SAP data. Retention gating ties evidence to a defined retention window.

sapctl audit-export --retain

EU CRA Annex IV statement

From 11 December 2027 the EU Cyber Resilience Act applies in full to sapctl as a “product with digital elements”. Our Annex IV technical documentation includes: product description, intended use, risk assessment, threat model, secure development lifecycle, vulnerability handling, applied harmonised standards, and a CE marking statement.

Latest draft Annex IV pack is available to customers and conformity assessors: [email protected].

Sub-processors

See the full sub-processor list and subscribe to the change feed.

Contact

[email protected] · for security disclosures, security policy.