Security
We have no certifications yet.
No SOC 2 report. No ISO certificate. No outside penetration test. No auditor hired. This page changes on the day any of that changes, and not before.
| Standard or law | Where we stand | Evidence today |
|---|---|---|
| SOC 2 | –No report | No auditor hired |
| ISO 27001 | –No certificate | Not on the roadmap |
| NIST CSF 2.0 | –Not started | The control mapping is not written |
| GovRAMP Snapshot | –Intended | No assessor hired, no date set |
| Penetration test | –None | Nobody outside has attacked it |
| WCAG 2.1 AA | +Self-issued | A published conformance statement |
| VPAT | –Not written | On the list, ahead of the security work |
| Plate reader laws | ×Out of scope | Nothing here reads plates |
| CJIS | ×Out of scope | We take in no criminal justice information |
| DPPA | ×Out of scope | We never look up a motor vehicle record |
| GDPR and the EU AI Act | ×Out of scope | Our first install is not in Europe |
| FedRAMP | ×Declined | Our buyers are not federal |
What you can check today is how it is built, not the paperwork. There is no person column. Object numbers retire when a thing leaves. Nothing here recognizes anyone or anything. Not a face, not a plate.
You can read all three in the control register and judge them yourself. None of it asks you to trust us.
We will write our controls in words a government reviewer already reads. That means the SOC 2 criteria: security, availability and confidentiality. It also means NIST CSF 2.0. CSF is short for Cybersecurity Framework, a US government standard. Then a reviewer can line our rows up with theirs. That work has not started. There is no mapping to ask us for.
GovRAMP is the security review that state and local buyers ask for. Our buyers are cities, state DOTs and transit agencies. That is the route that matters. It is open to a company with no revenue. The federal route is not. The first step is a twelve-month Security Snapshot against the top 40 NIST controls.
It is the path we mean to take. No assessor is hired. No date is set.
04 / Laws
The two rules a lawyer asks about first
Plate reader laws
California SB 34 and laws like it cover systems that read and keep plate characters. They require public meetings, a published use policy and access logs. They also limit what an agency may do with the data later.
Road Sentinel does not read plates. There is no plate reader in it. So there is no plate database, no hotlist and no plate lookup. We track everything that moves. We never learn who.
CJIS
Criminal justice information means records from FBI and state criminal justice systems. Road data from a private company is not on that list. Selling footage to a police department does not put us under CJIS.
CJIS would only reach us if we took that data in. So our agency request forms have no free-text field that invites a case number or a person. There is nowhere to type one. Saying no to that data is the stronger control.
- DPPA. The Driver's Privacy Protection Act covers motor vehicle records. Road Sentinel never looks one up and holds no plate characters. That data never reaches us.
- GDPR. It covers EU personal data and the watching of EU residents. Our first install is not in Europe. Nothing in the product picks a person out by face or body. The EU AI Act gets the same answer.
- FedRAMP. This is the federal path. Our first customers are cities, states and companies. So we are going after GovRAMP instead. FedRAMP is not on our roadmap, and we would rather say so than list it.
- Surveillance technology ordinances. Some cities make an agency file an impact report before it uses new technology. We write ours ahead of time, and it describes the real site. It ships with our first city contract.
- Accessibility. Section 508 and WCAG 2.1 AA sit in the same packet as the security questionnaire. Our statement is on accessibility. We wrote it ourselves. That is exactly what a conformance statement is.
Forge Core sells data. Some states make data brokers register. California, Texas, Oregon and Vermont each have a law. Our lawyers have to say whether we are one. We will publish the answer here, not guess at it.
Our record is keyed to a place and a time, not a person. It cannot be tied to a person. So we say it is not personal information. That is our argument. Nobody official has decided it.
Four short policies are not written yet. They cover retention, access control, incident response and acceptable use. There is no filled-in security questionnaire and no VPAT. The document register lists what exists and what does not.