Skip to main content

Trust center24 published policies10 frameworks

Security, privacy, and compliance,in writing.

We publish our written controls, our subprocessors, and where we stand on each framework, including the ones still in progress. Clients and auditors can request supporting documentation under NDA.

Verify an executed documentProgram integrity 24af664b6c…2253cb

01

Framework posturewhere each one stands.

NIST800-171

Self-assessed

Self-assessment posted to DoD SPRS, score 99 / 110 with closed POA&M.

SPRS UID SB00084980 · CAGE 9QA91 · assessed 2024-07-17 · Basic confidence

NextAnnual reassessment.

CMMC L1

Self-assessed

17 practices (FAR 52.204-21 derived) implemented and self-attested.

NextAnnual self-affirmation per 32 CFR 170.15.

FAR 52.204-21

Self-assessed

Basic safeguarding clause (15 controls), fully implemented across the platform.

NextContinuous.

GDPR

Self-assessed

Policies, DPAs, SCCs, retention schedule, and DSAR workbench operational.

NextContinuous.

CCPA

Self-assessed

Notice at collection, right-to-know, right-to-delete, and opt-out flows live.

NextContinuous.

NIST AI RMF

Self-assessed

Govern function fully implemented; AI Acceptable Use Policy + approved tools register.

NextContinuous; voluntary framework.

ESIGN/UETA

Self-assessed

In-house e-signature with audit trail, SHA-256 hashing, and 7-year WORM retention (S3 Object Lock COMPLIANCE).

NextContinuous.

SOC2

In progress

All design-effectiveness controls in place; weekly evidence pack feeding the operating-effectiveness window.

NextType I by 2026-Q4; Type II observation 2027-H1 (CPA engagement).

ISO27001

In progress

ISMS established; SSP, SoA, and POA&M drafted against Annex A 2022.

NextStage 1 audit 2027-Q1 (accredited certification body).

CMMC L2

In progress

Built on the NIST 800-171 baseline that already scores 99/110; CUI enclave design ready.

NextC3PAO assessment when first CUI contract requires it.

02

Attestationsverifiable at the source.

NIST800-171

99 / 110

NIST SP 800-171, DoD SPRS Self-Assessment

Self-assessment posted to the U.S. DoD Supplier Performance Risk System with a closed POA&M.

SPRS UID SB00084980 · CAGE 9QA91

Attested 2024-07-17

03

Policiespublished verbatim.

Confidential plans, such as incident response and business continuity, are available to clients and auditors under NDA.

governance

people

access

  • Access Control Policy

    How logical access to systems and data is granted, reviewed, modified, and revoked.

    SOC2ISO27001NIST800-171

    PDF
  • Password Policy

    Authentication requirements aligned with NIST SP 800-63B, including MFA.

    SOC2ISO27001NIST800-171

    PDF

data

infrastructure

development

operations

third party

privacy

04

Operational recordsthe living ones we publish.

05

Contactsecurity issues acknowledged within five business days.

Compliance

compliance@rexblack.com

Questions about our frameworks, security questionnaires, and auditor access.

Security

security@rexblack.com

Report a vulnerability, suspicious activity, or an incident.

Privacy

privacy@rexblack.com

Data-subject requests under GDPR, CCPA, and comparable laws.