HOME / TRUST & CERTIFICATION
Trust, Security & Certification

Built to the standard legal scrutiny demands.

RestfulSync is engineered to enterprise-grade security and compliance frameworks. Independent audits and formal certifications are underway. This page tracks that work in the open, and it will be updated with verified results and downloadable documentation as each review is completed.

Audit & Certification In Progress

The frameworks, tests, and certifications described below are the standards we are building and auditing against. They are targets in active progress, not completed or independently verified attestations. We will publish audit reports, test results, and certification documentation on this page as each one is finalized.

Independent AI compliance audit

Auditing against four rigorous frameworks.

An independent AI compliance audit is being conducted against four of the most demanding AI-governance and security frameworks available. It covers the compliance architecture, jurisdiction enforcement logic, forensic hash integrity, adversarial resistance, and evidence chain-of-custody controls.

Audit in progress
ISO 42001:2023

AI management systems

The international standard for responsibly developing and operating AI systems. For RestfulSync it governs the Compliance Decision Engine that applies recording-consent law across 51 jurisdictions.

Governance structureDecision-engine controlsJurisdiction logic
NIST AI RMF

AI risk management

A structured approach to managing risk across the AI lifecycle. The runtime compliance-verification flow is being assessed against Govern, Map, Measure, and Manage.

Runtime verification flowRisk categorizationBias + fairness controls
OWASP Agentic AI Top 10

Adversarial resistance

The critical security risks in AI-agent systems. An adversarial testing suite, jailbreak, prompt injection, roleplay induction, and context burial, is being run against the AI compliance layer.

Jailbreak resistanceLegal-services gate integrityHash integrity under attack
NIST 800-53

Security controls

The federal security-control framework referenced by FISMA. The security architecture, row-level security, WORM retention, MFA, SAML, evidence-log export, is being assessed against applicable control families.

Access controlAudit + accountabilityEvidence integrity
Compliance Decision Engine

51-jurisdiction enforcement, under continuous test.

The Compliance Decision Engine applies jurisdiction-specific recording behavior in real time. These are the enforcement rules its automated test suite covers. Results will be published here once the formal review is complete.

Verification in progress
RULE 01
Profile A enforcement

One-party consent states; gated user initiation before audio capture.

Under test
RULE 02
Profile B enforcement

All-party consent; overt protocol with auto video-only fallback.

Under test
RULE 03
Profile C enforcement

Context-specific treatment for communication type, privacy context, and jurisdiction-specific requirements, with video-only fallback where audio cannot be authorized.

Under test
RULE 04
Special-case jurisdiction enforcement

Washington, Connecticut, Nevada, Missouri, Oregon, and D.C. apply their own controlled runtime rules rather than one shared exception.

Under test
RULE 05
Consent-token tracking

All 51 jurisdictions; invite, accept, and revoke GPS tracking.

Under test
RULE 06
Cross-jurisdiction rule

Multi-participant; the most restrictive profile applied immediately.

Under test
RULE 07
Audio fail-safe

Muted device in Profile B/C switches to video-only.

Under test
RULE 08
COPPA VPC gate

Under-13 data collection blocked until VPC is validated server-side.

Under test
RULE 09
Minor SOS routing

Under-18 accounts route SOS to 911 and emergency contacts only.

Under test
RULE 10
Unknown jurisdiction

GPS or VPN ambiguity defaults to the strictest profile.

Under test
RULE 11
SOS 911 priority

Emergency calling bypasses every subscription and payment check.

Under test
Platform security testing

Role boundaries, tested across every admin role.

Role-based access control is being tested across every administrative role and permission domain in the platform, spanning the backend API, direct database access patterns, and browser UI role boundaries. The full results become part of the compliance documentation package as the review completes.

Hardening in progress
RBAC test coverage

Role boundary testing across roles, domains, and access-control logic.

Coverage spans five administrative roles and six permission domains, with TypeScript validation on backend and admin and production builds on both. The modules under test:

Vault impersonationPayout controllerAdmin invite confirmationImpersonation serviceQBO sync controllerAdmin access serviceJWT strategyApproval requestsExport artifactsRole permission boundariesDirect API testsE2E browser role tests
Freedom to operate

Design-arounds implemented at the engineering level.

A Freedom to Operate analysis is being conducted against existing safety-application patents. The design-around constraints it identified are implemented as mandatory backend rules, not recommendations, and are covered by the test suite.

FTO review in progress · Patent Pending
Implemented

On-device Safe Walk timers

Session timers run on the local device. The backend does not schedule or send missed check-in notifications. The phone sounds a local alarm when the timer expires. Timer expiration does not send an automatic alert; the user must choose Alert Contacts or SOS to escalate.

Implemented

No subgroup escalation

No different alerts to different contact subsets. All designated contacts are notified at once on explicit SOS activation.

Implemented

No pre-event buffer

No continuous pre-event recording. Recording begins at explicit user-initiated session start; no background pre-capture exists in the architecture.

Implemented

No clearinghouse layer

No third-party call-center decision layer. SOS puts a call to 911 in front of the user and, on eligible plans and where it is available, alerts an integrated emergency support service.

Implemented

SMS without live-map URLs

Pre-Trip SMS uses the native device composer, text-only, no live-map links. On-device reverse geocoding represents location.

Patent Pending

Active IP protection

Provisional applications filed, with a nonprovisional in preparation, covering the core safety architecture, evidence-delivery system, and AI compliance engine.

SOC 2 Type II roadmap

SOC 2 is on the roadmap, and the architecture is built for it.

Enterprise buyers in healthcare, government, and legal verticals often require SOC 2 Type II before contract execution. The security architecture is built to the controls SOC 2 evaluates; the formal certification process is planned.

Built-in

Security architecture

WORM, RLS, SAML, TOTP, and audit logging built into the core.

In place
In progress

Independent audit

NIST 800-53 controls assessed within the AI compliance audit.

Underway
Planned

SOC 2 Type I

Point-in-time controls assessment, on the roadmap.

Planned
Roadmap

SOC 2 Type II

Twelve-month operating-period assessment, planned.

Roadmap

If your organization requires SOC 2 Type II before contract execution:Request the compliance documentation package as it is finalized. It is being assembled from the NIST 800-53 assessment, the 51-state compliance matrix, the FTO summary, and the DPA, the same controls portfolio SOC 2 Type II evaluates.

Security architecture

Four security control categories, built into the core.

Access control & identity

SAML 2.0 SSO with Okta and Microsoft Entra. SCIM 2.0 automated deactivation on employee exit. TOTP MFA for government accounts. Break-glass recovery documented. Postgres row-level security at the database layer.

Audit & accountability

Tamper-evident audit log across all evidence-access events. Pseudonymous server identity per event. Dual timestamps, server-received and device-captured. Jurisdiction and confidence logged. CJIS evidence-access log export for the government edition.

Evidence integrity

Write-once-read-many (WORM) retention. SHA-256 per-chunk hashing at capture and a manifest fingerprint over the archive. Legal Hold blocks deletion jobs. Retention of one year on Plus and seven years on Premium and Family.

Data protection & residency

TLS in transit, encryption at rest on device and server. US data residency for the government edition. Sub-processor DPAs. Per-jurisdiction remote kill switch via feature flag.

Documentation package

One request covers what procurement needs.

Being assembled for qualified enterprise prospects. A signed DPA and MSA are required before an organization is activated and before any data enters the system.

Data Processing Agreement

Covers all sub-processors. Signed before org activation.

Enterprise MSA

Standard template for legal review. PO and ACH net-30 for government accounts.

51-state compliance matrix

Jurisdiction-by-jurisdiction recording-consent profiles with enforcement specs.

Backend test results

Compliance and platform test documentation, published as the review completes.

FTO summary

Freedom to Operate analysis and the design-around constraints implemented.

AI audit framework summary

ISO 42001, NIST AI RMF, OWASP Agentic AI Top 10, and NIST 800-53 scope and findings.

RestfulSync's audits, certifications, and test attestations are in progress and are not yet independently verified or finalized. Nothing on this page should be read as a completed certification. Framework names are the property of their respective owners and are referenced to describe the standards RestfulSync is auditing against. This page will be updated with verified results and documentation as each review is completed.

We use cookies to understand how the site is used. Nothing loads and no analytics fire until you choose. See our Cookie Policy.