Certifications & compliance

Independently audited, continuously monitored, evidenced on request

Guardian holds the attestations that regulated buyers actually ask for, and we publish the audit calendar, the framework mapping and the residency model behind them. Everything on this page is available as evidence you can hand to an assessor — most of it the same day you ask.

Current attestations

Certifications and audit reports held by Guardian

Scope statements matter more than logos. Each entry below names the auditor, the report period and exactly which parts of the Guardian estate are in scope — because a certification covering only the corporate website is worth nothing to a security buyer.

AICPA

SOC 2 Type II

All five Trust Services Criteria — security, availability, processing integrity, confidentiality and privacy. Covers the Sentinel platform, sensors, the analyst console, the public API and the supporting production infrastructure in every commercial region.

Auditor
Halloway & Reid LLP
Current period
1 Oct 2025 – 30 Sep 2026
Report issued
November, annually
ISO/IEC

ISO/IEC 27001:2022

Information security management system covering the design, development, delivery and support of the Sentinel platform and Guardian managed services, across all engineering and SOC locations. Statement of Applicability available on request.

Certification body
Verity Assurance International
Certificate valid
Jun 2025 – Jun 2028
Surveillance
Annual, May–June
CLOUD

ISO/IEC 27017 & 27018

Cloud-specific security controls (27017) and protection of personally identifiable information in public clouds (27018), audited alongside the 27001 management system by the same certification body under a combined scope.

Certification body
Verity Assurance International
Certificate valid
Jun 2025 – Jun 2028
Also held
ISO/IEC 27701 privacy extension
FEDRAMP

FedRAMP High

Authorised at the High impact level for the Guardian Government Cloud, sponsored by a cabinet-level agency, with continuous monitoring deliverables submitted monthly. DoD Impact Level 5 provisional authorisation held for the same environment.

3PAO
Castellan Federal Assessors
Authorised since
March 2023
Annual assessment
March–April
PCI DSS

PCI DSS v4.0, Level 1

Assessed as a Level 1 service provider for the components of Sentinel that may process cardholder data telemetry on behalf of customers. Attestation of Compliance and responsibility matrix are issued to customers for their own assessments.

QSA
Bellweather Security QSA Ltd
Assessment window
August–September, annually
AoC issued
October, annually
HIPAA

HIPAA & HITRUST

Guardian executes a Business Associate Agreement with covered entities and business associates, and holds HITRUST CSF r2 certification for the healthcare-scoped environment. Safeguards are mapped to the Security Rule at control level.

Assessor
Halloway & Reid LLP
HITRUST valid
Feb 2025 – Feb 2027
BAA
Available on all plans
GDPR

GDPR, UK GDPR & DPF

Guardian acts as processor for customer telemetry under a Data Processing Addendum incorporating the 2021 Standard Contractual Clauses and the UK Addendum. Certified under the EU–US and UK Data Privacy Frameworks; EU representative appointed in Ireland.

Lead authority
Irish Data Protection Commission
Transfer impact assessment
Published, reviewed annually
CSA STAR

CSA STAR Level 2

Third-party attested against the Cloud Controls Matrix v4, with a completed Consensus Assessments Initiative Questionnaire published to the STAR registry. Most customer security questionnaires can be answered directly from it.

Registry entry
Public, updated annually
CCM version
v4.0.7
CAIQ
Downloadable without NDA
REGIONAL

Regional schemes

IRAP assessed to PROTECTED for the Australian region, BSI C5:2020 attestation for Germany, TISAX AL3 for automotive customers, Cyber Essentials Plus in the UK, and ENS Medio for Spanish public sector.

IRAP
PROTECTED, assessed 2025
C5
Type 2 attestation, annual
TISAX
Assessment Level 3
Scope statements, not badges. Every certificate, attestation letter and scope statement listed above is available in full. Where a scope excludes part of the estate — for example, the Government Cloud is deliberately out of scope for the commercial SOC 2 report and covered by FedRAMP instead — that exclusion is stated on the certificate itself. Request the document pack.

Audit cadence

A twelve-month assurance calendar, not an annual scramble

Compliance evidence is generated continuously by the same pipelines that run the platform, so audits are a sampling exercise rather than a discovery exercise. This is the standing calendar; dates shift by a few weeks but the sequence does not.

JanFebMar AprMayJun JulAugSep OctNovDec SOC 2 Type II observation SOC 2 report issued ISO 27001 / 27017 / 27018 surveillance FedRAMP continuous monitoring FedRAMP annual assessment PCI DSS assessment (ROC) HIPAA / HITRUST control review Independent penetration tests Subprocessor & DR exercises Continuous, 12-month window External audit activity Report or authorisation milestone Offensive testing Internal resilience exercise
11 External audits and assessments completed in the last 12 months
0 Qualified opinions or material exceptions across all reports since 2019
1,840 Controls under continuous automated evidence collection
96% Of audit evidence produced automatically rather than assembled by hand

Framework coverage

How Guardian's controls map to the frameworks you report against

Two questions matter to a compliance team: is the vendor itself compliant, and does the product help me become compliant. The table separates the two, because a vendor's own certificate does nothing for your audit if the product produces no evidence.

Guardian's own attestation status, and the product capabilities that support your programme.
Framework Guardian status Product support for your programme Evidence you can export
SOC 2 (TSC 2017) Type II Control monitoring for logical access, change management and system operations Continuous control status, exception register, evidence packets
ISO/IEC 27001:2022 Certified Annex A technical control coverage with automated gap reporting SoA mapping export, control effectiveness history
NIST CSF 2.0 Aligned Function-level scoring across Govern, Identify, Protect, Detect, Respond, Recover Maturity scorecard, trend over 24 months
NIST SP 800-53 Rev 5 FedRAMP High Control inheritance statements and a customer responsibility matrix Inheritance letter, POA&M extract
PCI DSS v4.0 Level 1 SP File integrity monitoring, log retention, segmentation validation evidence AoC, responsibility matrix, quarterly evidence pack
HIPAA Security Rule BAA offered PHI discovery, access monitoring and breach investigation timelines Access reports, disclosure accounting extracts
GDPR / UK GDPR Processor, DPF certified Data discovery, residency enforcement, subject request support DPA, TIA, records of processing extract
DORA (EU financial entities) Contractually aligned ICT incident classification, register of information fields, resilience testing Incident register export, subcontracting chain
NIS2 (EU essential entities) Contractually aligned 24-hour early-warning workflow and supply chain risk reporting Notification timeline export
CMMC 2.0 Level 2 Supports assessment CUI marking, boundary monitoring and audit record protection Practice-level evidence mapping
APRA CPS 234 / CPS 230 Aligned Information asset classification and testing evidence for regulated entities Control testing register
CIS Critical Controls v8.1 Aligned Implementation group scoring across all 18 controls IG1–IG3 scorecard, per-safeguard status

Scroll the table sideways to see evidence columns.

Need help closing the gap rather than measuring it? Guardian's compliance advisory practice runs readiness assessments and remediation programmes against every framework listed here.

Data residency

Choose where your telemetry lives — and keep it there

Residency is selected when a tenant is created and enforced by the platform rather than by policy. Ingestion, indexing, analytics, backups and search results all remain in the chosen region. Cross-region access by Guardian personnel requires your per-case approval and is recorded in your audit log.

Oregon N. Virginia Montréal São Paulo London Frankfurt Dubai Mumbai Singapore Tokyo Sydney US Gov Commercial residency region — minimum three availability zones FedRAMP High / IL5 environment, US persons only
Region placement is illustrative. Each region is served by at least three physically separate availability zones; backups remain in region unless you explicitly enable cross-region replication for your own resilience requirements.
Residency regions, in-region backup and applicable regional schemes.
Region Identifier In-region backup Regional schemes in scope
United States (East)us-east-1YesSOC 2, PCI DSS, HIPAA, CSA STAR
United States (West)us-west-2YesSOC 2, PCI DSS, HIPAA, CSA STAR
US Governmentus-gov-highYesFedRAMP High, DoD IL5, CJIS, ITAR
Canadaca-central-1YesSOC 2, PIPEDA, Protected B
Brazilsa-east-1YesSOC 2, LGPD
United Kingdomuk-south-1YesUK GDPR, Cyber Essentials Plus, G-Cloud
European Unioneu-central-1YesGDPR, BSI C5, TISAX, ENS, DORA-aligned
Gulf regionme-central-1YesSOC 2, UAE IA, Saudi NCA ECC
Indiaap-south-1YesSOC 2, DPDP Act, CERT-In directions
Singaporeap-southeast-1YesSOC 2, MAS TRM-aligned, PDPA
Japanap-northeast-1YesSOC 2, ISMAP-aligned, APPI
Australiaap-southeast-2YesIRAP PROTECTED, APRA CPS 234-aligned

Scroll the table sideways to see all columns.

Document library

Get the evidence pack

Documents marked open download immediately. Documents marked NDA are released through the trust portal once a mutual non-disclosure agreement is in place — usually the same business day, and existing customers already covered by their master agreement skip the step entirely.

AttestationPDF · 84 pagesNDA

SOC 2 Type II report

Full report including the auditor's opinion, system description, control objectives and the complete results of testing for the current observation period.

Request access
CertificatePDF · 3 pagesOpen

ISO 27001, 27017, 27018 certificates

Current certificates with scope statements and certification body registration numbers, plus the Statement of Applicability summary.

Download
QuestionnaireXLSX · CAIQ v4Open

CSA CAIQ (Consensus Assessments)

Completed CAIQ against Cloud Controls Matrix v4.0.7. Answers most vendor security questionnaires without a bespoke response cycle.

Download
AssessmentPDF · 12 pagesNDA

Penetration test summary letters

Executive summaries for the four most recent independent tests, with finding counts by severity and remediation status. Full technical reports for Enterprise customers.

Request access
LegalPDF · 22 pagesOpen

Data Processing Addendum & SCCs

The standing DPA including the 2021 Standard Contractual Clauses, UK Addendum, Swiss annex and the current subprocessor schedule.

Read the privacy policy
AssessmentPDF · 18 pagesOpen

Transfer impact assessment

Guardian's assessment of the legal regimes affecting international transfers, supplementary measures applied, and the government access request record.

Download
ArchitecturePDF · 34 pagesNDA

Security architecture whitepaper

Detailed description of tenant isolation, key management, network design and the control plane for architects who need to challenge the model.

Trust & security
AuthorisationPackageAgency

FedRAMP security package

System Security Plan, SAR, POA&M and continuous monitoring artefacts, released to agencies through the FedRAMP secure repository.

Government & defence
ReferenceXLSXOpen

Customer responsibility matrix

Control-by-control statement of what Guardian operates, what you operate, and what is shared — the document your auditor will actually ask for.

Download

Need something that is not listed?

Security questionnaires, bespoke control mappings, insurance certificates, business continuity plan summaries and modern-slavery statements are all available. Send the request to [email protected] with your organisation name and the framework you are reporting against.

Contact the compliance team

Sector and regional obligations

What Guardian does for your specific regime

DORA — EU financial entities

Guardian contracts include the mandatory DORA provisions for ICT third-party service providers: exhaustive service descriptions, data processing locations, notice periods, exit strategies, subcontracting conditions and the right of access, inspection and audit for both you and your competent authority.

Operationally, Sentinel classifies ICT-related incidents against the DORA criteria and produces the initial, intermediate and final notification content within the regulatory windows. Register of information fields are exported in the supervisory template. See Financial services.

NIS2 — EU essential and important entities

The platform tracks the 24-hour early warning, 72-hour notification and one-month final report obligations as a single incident workflow with countdown timers, so the deadline is visible to the responder rather than buried in a policy document.

Supply chain security requirements are supported through third-party risk monitoring and the exportable subprocessor chain described on Trust & security.

HIPAA and the HITECH breach rules

Guardian signs a Business Associate Agreement on every plan at no extra cost. Technical safeguards under §164.312 — access control, audit controls, integrity, authentication and transmission security — are implemented and evidenced in the SOC 2 report and HITRUST certification.

For breach determination, Sentinel reconstructs exactly which records were accessed, by which identity, from where, and whether the data was encrypted at the time, which is the difference between a reportable breach and a documented non-event.

PCI DSS v4.0 responsibilities

Guardian is assessed annually as a Level 1 service provider and issues an Attestation of Compliance together with a responsibility matrix covering all twelve requirement areas. Requirements 10 (logging and monitoring), 11 (testing) and 12 (policy support) are where most customers inherit meaningful coverage.

The 2025 future-dated requirements — including targeted risk analyses and automated log review — are already implemented rather than deferred.

Government access requests and transparency

Guardian requires valid legal process for any government request for customer data, challenges overbroad or improperly served demands, and notifies the affected customer unless legally prohibited from doing so. Where a gag order applies, we challenge it and notify as soon as the prohibition lapses.

We publish a transparency report twice a year covering the number of requests received by category, the number complied with in whole or in part, and the number rejected. To date Guardian has never provided a government with bulk access to customer telemetry, and we have never received a request for a systemic backdoor.

Audit rights and on-site assessment

Enterprise customers and their regulators have contractual audit rights. In practice most requirements are satisfied by the SOC 2 report, ISO certificates and the CAIQ, so our first offer is always documentation. Where documentation is genuinely insufficient, we accommodate a scoped assessment with 30 days' notice, once per year, at no charge.

Regulated customers subject to DORA, CPS 230 or equivalent regimes get audit and inspection rights extended to their supervisory authority as standard contract terms rather than as a negotiated concession.

From evidence to outcome

Compliance work Guardian removes from your calendar

  1. Continuous control monitoring

    Sentinel evaluates your estate against the framework you select and reports control status continuously, so the quarter-end evidence hunt becomes an export rather than a project. Drift is flagged the day it happens, not the week before the audit.

  2. Evidence generation

    Screenshots, configuration snapshots, access reviews and log samples are collected automatically with cryptographic timestamps, packaged per control and handed to your auditor in the format they asked for.

  3. Questionnaire acceleration

    The completed CAIQ, SIG Lite responses and framework mappings answer the majority of inbound customer security questionnaires directly, which matters most if you are yourself a supplier being assessed.

  4. Audit-ready incident records

    Every incident carries an immutable timeline: what was detected, when, who acted, what was contained and what was notified. That record is what turns a regulator conversation from an argument into a review.

Give your auditors a shorter list

Request the full evidence pack, or book a working session with Guardian's compliance team and your assessors to map our controls onto your framework line by line.