Skip to main content
We pass our own audits before we ask you to pass yours

Security as a primitive, not a marketing page.

ReguNav™ is built on the same primitives we ask our customers to demonstrate. Live posture, not a snapshot — every signal you read here is also exposed at trust.regunav.com for your vendor-due-diligence team.

Architecture

Encryption

Compliance posture

StandardStatus
SOC 2 Type IIType I report Q3 2026 · Type II observation in progress
ISO/IEC 27001:2022Stage 1 audit Q4 2026
ISO/IEC 42001:2023 (AIMS)Internal AIMS active · external audit Q1 2027
GDPRArt 32 implemented · DPO designated · DPIA template published
EU AI ActSelf-classified as not-high-risk · Art 50 transparency live · Art 4 AI-literacy training mandated
HIPAABAA available on Enterprise · technical safeguards in place
DORAInternal ICT-risk framework deployed · third-party register live

Incident response

24×7 paging via PagerDuty · SOC ticket triage SLA <15 min for P1 · public status page at status.regunav.com · GDPR-compliant breach notification within 72 hours · DORA major-incident reporting within the regulatory window.

Vulnerability disclosure

Responsible-disclosure email: security@regunav.com (PGP key at /.well-known/security.txt). Bug bounty on HackerOne for Enterprise customers. Safe-harbour for good-faith researchers.