ISO/IEC 27001:2022
Cognitive Server control mapping & evidence matrix
Perimetral enforcement
Shield · Role-based access matrix
FIG. 05 · RBAC MATRIX, ENFORCED PERIMETRALLY
| Control | Description | Owner · Capability | Cross-mapped to | Cover |
|---|---|---|---|---|
| A.5.15 | Access control | Fabric · SHIELDSSO + scoped tokens | GDPR Art.32SOC2 CC6.1 | ✓ |
| A.5.17 | Authentication information | Fabric · SHIELDOAuth 2.1 PKCE | NIST 800-63 | ✓ |
| A.5.23 | Information security for cloud services | App · NEXUSSovereign on-prem perimeter | NIS2 Art.21 | ✓ |
| A.6.3 | Information security awareness | App · NEXUSOperator playbooks + training records | SOC2 CC1.4 | ✓ |
| A.7.4 | Physical security monitoring | Fabric · SHIELDTPM 2.0 attestation (hardware vendor) | NIS2 Art.21 | ✓ |
| A.8.3 | Information access restriction | App · VAULTVDS row-level policies | GDPR Art.5 | ✓ |
| A.8.5 | Secure authentication | Fabric · SHIELDJWT + Tenant-ID isolation | NIST 800-63SOC2 CC6.1 | ✓ |
| A.8.10 | Information deletion | App · VAULTVDS lifecycle | GDPR Art.17 | ✓ |
| A.8.12 | Data leakage prevention | App · COREInside-perimeter inference, zero egress | GDPR Art.32 | ✓ |
| A.8.15 | Logging | Fabric · CHAINTrace ID per request | SOC2 CC7.2NIS2 | ✓ |
| A.8.16 | Monitoring activities | Fabric · CHAINHeartbeat + alert engine | NIS2 Art.21 | ✓ |
| A.8.28 | Secure coding | Fabric · BRIDGECode signing + SBOM | SLSA L3 | ◐ |
Showing 12 representative controls of 93. Full matrix available on request under NDA.
Artifacts behind every control
Each mapped control is backed by reproducible artifacts: signed configurations, trace exports, attestation reports and policy bundles. Auditors receive a read-only view of the evidence repository scoped to their engagement.
Independent assessments
- 2026-04Passed
ISO/IEC 27001:2022 — surveillance audit
Bureau Veritas. Zero major non-conformities. 2 observations on access-review cadence — closed.
- 2025-11Passed
SOC 2 Type II — annual
Trust Services Criteria across Security, Availability, Confidentiality. Unqualified opinion.
- 2025-09Passed
NIS2 readiness review
Internal mapping against Art.21 controls completed for all four cognitive applications.
- 2025-06Passed
ISO/IEC 27001:2022 — initial certification
Stage 1 + Stage 2 audit completed. Certificate issued for the Cognitive Server platform.
- 2025-03Passed
Penetration test (external)
Black-box and grey-box assessment. 0 critical, 1 high (patched), 4 medium (patched).