Controlled infrastructure representing security and assurance

Security and assurance

Security claims you can verify

OpenFactory separates controls in the product from certifications held by the company. Review what is available now, what must be validated in a pilot, and what is still part of the readiness program.

Published capability statusArtifact and test evidenceNo implied certification

Evidence in the product today

These capabilities produce concrete records a technical reviewer can inspect. They support a customer control environment but do not, by themselves, certify the company or the customer workload.

Artifact inventory

Supported image workflows generate hash-bound CycloneDX software inventories and preserve explicit coverage information.

Runtime validation

Produced images can be booted in isolated VMs and exercised with terminal, service, desktop, or visual checks.

Access boundaries

Authenticated APIs, organization-scoped sharing, role-aware administration, and VM isolation constrain access to platform resources.

Current status

External certification status

OpenFactory does not currently claim SOC 2 Type II or ISO/IEC 27001 certification. Readiness work is being established before independent audit activity. Until a certification is completed and independently verifiable, the status remains not certified.

SOC 2 Type II

Readiness program being established

Not certified. Control inventory, ownership, evidence retention, and audit-readiness work must be completed before an independent Type II examination.

ISO/IEC 27001

Readiness program being established

Not certified. ISMS scope, risk treatment, control operation, and internal review must be established before certification assessment.

A useful security review starts with the workload

Share the image, data boundary, deployment model, and evidence requirements. We will distinguish available controls from pilot integrations and unresolved gaps.

  • Product architecture and deployment boundary discussion
  • Artifact, SBOM, and VM test evidence review
  • Data flow and retention questions
  • Written fit, gap, and follow-up items

Request a technical security review

Tell us what you are evaluating and which assurance requirements are gating the decision.

Security questions

Is OpenFactory SOC 2 Type II certified?

No. OpenFactory does not currently claim SOC 2 Type II certification. A readiness program is being established before an independent examination.

Is OpenFactory ISO/IEC 27001 certified?

No. OpenFactory does not currently claim ISO/IEC 27001 certification. ISMS readiness work must precede an external certification assessment.

Can OpenFactory operate in a customer-controlled environment?

Customer-cloud, on-premises, and disconnected requirements are scoped through a technical pilot. Availability depends on the workload, integrations, and operating boundary.

How do I report a vulnerability?

Send a private report to security@openfactory.tech with reproduction details and potential impact. Do not include secrets or unrelated personal data.