Trust center24 published policies10 frameworks
Security, privacy, and compliance,in writing.
We publish our written controls, our subprocessors, and where we stand on each framework, including the ones still in progress. Clients and auditors can request supporting documentation under NDA.
01
Framework posturewhere each one stands.
NIST800-171
Self-assessedSelf-assessment posted to DoD SPRS, score 99 / 110 with closed POA&M.
SPRS UID SB00084980 · CAGE 9QA91 · assessed 2024-07-17 · Basic confidence
NextAnnual reassessment.
CMMC L1
Self-assessed17 practices (FAR 52.204-21 derived) implemented and self-attested.
NextAnnual self-affirmation per 32 CFR 170.15.
FAR 52.204-21
Self-assessedBasic safeguarding clause (15 controls), fully implemented across the platform.
NextContinuous.
GDPR
Self-assessedPolicies, DPAs, SCCs, retention schedule, and DSAR workbench operational.
NextContinuous.
CCPA
Self-assessedNotice at collection, right-to-know, right-to-delete, and opt-out flows live.
NextContinuous.
NIST AI RMF
Self-assessedGovern function fully implemented; AI Acceptable Use Policy + approved tools register.
NextContinuous; voluntary framework.
ESIGN/UETA
Self-assessedIn-house e-signature with audit trail, SHA-256 hashing, and 7-year WORM retention (S3 Object Lock COMPLIANCE).
NextContinuous.
SOC2
In progressAll design-effectiveness controls in place; weekly evidence pack feeding the operating-effectiveness window.
NextType I by 2026-Q4; Type II observation 2027-H1 (CPA engagement).
ISO27001
In progressISMS established; SSP, SoA, and POA&M drafted against Annex A 2022.
NextStage 1 audit 2027-Q1 (accredited certification body).
CMMC L2
In progressBuilt on the NIST 800-171 baseline that already scores 99/110; CUI enclave design ready.
NextC3PAO assessment when first CUI contract requires it.
02
Attestationsverifiable at the source.
NIST800-171
99 / 110NIST SP 800-171, DoD SPRS Self-Assessment
Self-assessment posted to the U.S. DoD Supplier Performance Risk System with a closed POA&M.
SPRS UID SB00084980 · CAGE 9QA91
Attested 2024-07-17
03
Policiespublished verbatim.
Confidential plans, such as incident response and business continuity, are available to clients and auditors under NDA.
governance
- Information Security PolicyPDF
The top-level commitment and principles governing how Rex Black protects information.
SOC2ISO27001NIST800-171
- Risk Management PolicyPDF
Qualitative risk methodology aligned with ISO 27005 and NIST SP 800-30.
SOC2ISO27001NIST800-171
people
- Acceptable Use PolicyPDF
What personnel may and may not do with Rex Black systems, data, and identity.
SOC2ISO27001
- Human Resources Security PolicyPDF
Pre-employment, onboarding, role changes, and off-boarding for personnel.
SOC2ISO27001NIST800-171
- Security Training & Awareness PolicyPDF
Mandatory curriculum, delivery, and phishing testing for all personnel.
SOC2ISO27001NIST800-171
- AI Acceptable Use PolicyPDF
Approved AI tools and prohibitions for handling Rex Black and client data.
SOC2ISO27001NIST AI RMFEU AI Act
access
- Access Control PolicyPDF
How logical access to systems and data is granted, reviewed, modified, and revoked.
SOC2ISO27001NIST800-171
- Password PolicyPDF
Authentication requirements aligned with NIST SP 800-63B, including MFA.
SOC2ISO27001NIST800-171
data
- Data Classification & Handling PolicyPDF
How data is classified and what handling rules apply to each level.
SOC2ISO27001NIST800-171GDPR
- Data Retention & Disposal PolicyPDF
How long each class of data is kept and how it is destroyed at end of life.
SOC2ISO27001NIST800-171GDPRCCPA
infrastructure
- Backup & Recovery PolicyPDF
Backup configurations and restoration targets (RPO/RTO) for every data class.
SOC2ISO27001NIST800-171
- Cryptography & Key Management PolicyPDF
Approved algorithms, key strengths, KMS usage, and the lifecycle of keys.
SOC2ISO27001NIST800-171
- Encryption StandardPDF
Operational detail of encryption in transit, at rest, in use, and in export.
SOC2ISO27001NIST800-171
- Network Security PolicyPDF
Edge, WAF, segmentation, and administrative access for Rex Black networks.
SOC2ISO27001NIST800-171
- Endpoint Security PolicyPDF
Baseline controls for laptops and mobile devices that process Rex Black data.
SOC2ISO27001NIST800-171
development
- Change Management PolicyPDF
Source-control, review, CI, and deployment discipline for code and infrastructure.
SOC2ISO27001NIST800-171
- Secure Software Development PolicyPDF
Security practices integrated across the software lifecycle from design to retirement.
SOC2ISO27001NIST800-171
operations
- Asset Management PolicyPDF
How information assets are inventoried, owned, classified, and lifecycled.
SOC2ISO27001NIST800-171
- Vulnerability Management PolicyPDF
Discovery, triage, remediation SLAs, and coordinated disclosure process.
SOC2ISO27001NIST800-171
- Logging & Monitoring PolicyPDF
What Rex Black logs, retention, tamper evidence, and real-time monitoring.
SOC2ISO27001NIST800-171
third party
- Vendor & Subprocessor Management PolicyPDF
Onboarding, monitoring, and termination of third parties handling Rex Black data.
SOC2ISO27001NIST800-171GDPR
- Third-Party Risk Assessment PolicyPDF
Tiering, scoring, and contractual requirements for every vendor relationship.
SOC2ISO27001NIST800-171
privacy
- Privacy Policy (Internal)PDF
How Rex Black personnel handle personal data on behalf of employees, prospects, and clients.
SOC2GDPRCCPAISO27001
- Data Subject Rights PolicyPDF
How Rex Black handles access, deletion, portability, and related rights.
SOC2GDPRCCPA
04
Operational recordsthe living ones we publish.
05
Contactsecurity issues acknowledged within five business days.
Compliance
compliance@rexblack.comQuestions about our frameworks, security questionnaires, and auditor access.