Artifact inventory
Supported image workflows generate hash-bound CycloneDX software inventories and preserve explicit coverage information.

Security and assurance
OpenFactory separates controls in the product from certifications held by the company. Review what is available now, what must be validated in a pilot, and what is still part of the readiness program.
These capabilities produce concrete records a technical reviewer can inspect. They support a customer control environment but do not, by themselves, certify the company or the customer workload.
Supported image workflows generate hash-bound CycloneDX software inventories and preserve explicit coverage information.
Produced images can be booted in isolated VMs and exercised with terminal, service, desktop, or visual checks.
Authenticated APIs, organization-scoped sharing, role-aware administration, and VM isolation constrain access to platform resources.
Current status
OpenFactory does not currently claim SOC 2 Type II or ISO/IEC 27001 certification. Readiness work is being established before independent audit activity. Until a certification is completed and independently verifiable, the status remains not certified.
Not certified. Control inventory, ownership, evidence retention, and audit-readiness work must be completed before an independent Type II examination.
Not certified. ISMS scope, risk treatment, control operation, and internal review must be established before certification assessment.
Share the image, data boundary, deployment model, and evidence requirements. We will distinguish available controls from pilot integrations and unresolved gaps.
No. OpenFactory does not currently claim SOC 2 Type II certification. A readiness program is being established before an independent examination.
No. OpenFactory does not currently claim ISO/IEC 27001 certification. ISMS readiness work must precede an external certification assessment.
Customer-cloud, on-premises, and disconnected requirements are scoped through a technical pilot. Availability depends on the workload, integrations, and operating boundary.
Send a private report to security@openfactory.tech with reproduction details and potential impact. Do not include secrets or unrelated personal data.