ROS is a security decision platform. The people who buy it are CISOs and security-conscious operators who will scrutinize our own posture before they trust us with a connector to theirs. This page explains — specifically and honestly — how we protect what you share with us.
Written by the Sapien9 security team. Last reviewed July 2026.
Each section below maps to a specific design decision or implementation detail — not a marketing claim. Where we cite technical specifics, you can verify them in the source.
ROS connectors that use your provider APIs (AWS, GitHub, Okta, Google Workspace) communicate exclusively through read-only API calls and cannot write, create, update, or delete resources. The one exception is the external attack-surface scan, which — by nature — sends network requests; it uses only safe, non-intrusive detection probes (never exploitation) against the targets you explicitly designate, and holds no credentials to your systems.
ROS requests the minimum token scope required to read the specific signals it assesses. You are never asked for administrative or write access.
Every credential and session token ROS persists is encrypted using modern, authenticated cryptography. We do not store plaintext secrets.
ROS stores security findings, evidence artifacts, and assessment metadata — not your data plane. We do not exfiltrate user records, application data, or business content.
Every assessment, connection, finding, and evidence artifact is scoped to an organization. Cross-tenant data access is prevented at the data model level.
Every assessment run, finding, and evidence artifact is persisted with a timestamp and provenance. You always know what was checked, when, and what was found.
We will not overstate our certification status. The table below reflects the current, honest state of our compliance program. We update it as status changes.
SOC 2 Type II — in progress. We are building the operational controls and evidence collection program required for a Type II audit. We will share the report under NDA with enterprise customers and partners when it is complete.
ROS maps all findings and evidence to NIST CSF 2.0 functions (Identify, Protect, Detect, Respond, Recover). The platform is designed around this framework at the data model level.
ROS does not store PHI. Customers in healthcare use ROS to assess their own HIPAA technical safeguard posture. A Business Associate Agreement (BAA) is available for enterprise customers.
CMMC Level 2 assessment support is on the roadmap. ROS already maps findings to NIST SP 800-171 controls, which form the CMMC L2 practice set.
AI governance assessments within ROS are structured around the NIST AI RMF (Map, Measure, Manage, Govern) taxonomy. The platform itself is evaluated against these principles.
ISO 27001 certification is on the compliance roadmap following SOC 2 Type II completion.
Honest disclosure: SOC 2 Type II is in progress, not complete. If your procurement process requires a current SOC 2 Type II report, please contact us to discuss a design-partner arrangement with contractual security commitments while we complete the audit cycle.
We maintain a complete list of subprocessors and will notify customers of material changes with reasonable advance notice.
AI reasoning engine. ROS sends anonymized, structured finding summaries to Claude for risk-prioritization reasoning and narrative generation. Raw credentials and PII are never included in these payloads.
Privacy policyApplication hosting, database, and object storage. ROS operates on infrastructure in US and EU regions. Data residency preferences are available for enterprise customers.
Privacy policyAnthropic payload scope: When ROS sends data to the Claude API for reasoning, it sends structured finding summaries — control IDs, severity, remediation text, and resource identifiers (e.g., a repo name or IAM policy name). It does not send raw API tokens, passwords, S3 object contents, user email addresses from identity providers, or any other credential or personal data. Anthropic processes these payloads under their API Terms of Service and Privacy Policy.
If you believe you have found a security vulnerability in ROS, please report it responsibly. We commit to acknowledging your report within two business days and to keeping you informed as we work toward remediation.
Security questionnaires, penetration test requests, and compliance inquiries are also welcome at the same address.
PGP key available on request. Please do not report vulnerabilities via public GitHub issues.
The public demo runs on a fictional, anonymized client with seeded data — no real systems are touched. In a real assessment, every API-connector call is read-only and the external surface scan is non-intrusive. You can watch the agent reason about findings in real time.