Skip to main content
AgentVault’s architecture is designed with compliance in mind from day one. This document maps AgentVault’s security controls to SOC 2 Trust Service Criteria and ISO 27001 Annex A controls, providing a reference for auditors and enterprise security teams.
AgentVault is not yet SOC 2 or ISO 27001 certified. This mapping documents how the platform’s architecture and controls align with these frameworks and identifies the path to formal certification.

SOC 2 Trust Service Criteria Mapping

CC1 — Security (Common Criteria)

The security principle addresses protection of system resources against unauthorized access.

CC2 — Confidentiality

The confidentiality principle addresses protection of information designated as confidential.

CC3 — Availability

The availability principle addresses whether the system is available for operation and use.

CC4 — Processing Integrity

The processing integrity principle addresses whether system processing is complete, valid, and authorized.

ISO 27001 Annex A Mapping

A.5 — Information Security Policies

A.6 — Organization of Information Security

A.8 — Asset Management

A.9 — Access Control

A.10 — Cryptography

A.12 — Operations Security

A.13 — Communications Security

A.16 — Information Security Incident Management

The ISO 27001 mapping above covers architectural controls. Organizational controls (policies, training, HR security) require additional documentation beyond the scope of this technical mapping.

Compliance Readiness Summary


Gap Analysis

The following items are identified as gaps requiring attention before formal certification: