Skip to content
This repository has been archived by the owner on Mar 17, 2023. It is now read-only.

Latest commit

 

History

History
47 lines (31 loc) · 2.2 KB

compliance-resources.md

File metadata and controls

47 lines (31 loc) · 2.2 KB

Compliance Resources and Certifications

On this page, we provide you with resources around compliance of Rocket.Chat with industry standards, regulations and best practices. Also our certifications are listed here. Contact our specialists for further information under security@rocket.chat.

Each resource is tagged with a section to indicate the scope. Some resources only apply to our hosted services, others to our self-managed product or else.

Compliance certifications

ISO 27001 certification

{% hint style="info" %} Scope: Hosted Offering, App Store, Software Development {% endhint %}

Rocket.Chat is ISO 27001 certified. ISO 27001 is an internationally recognized standard for information security management systems. Our organization is audited on an annual basis by an independent third-party auditor to verify the design and operational effectiveness of the management system.

  • Certificate:

{% file src="../../.gitbook/assets/Certificate 2020.pdf" %} ISO 27001 certificate 2020 {% endfile %}

  • Name: ISO 27001 Information Security Management Systems
  • Statement of applicability (link)
    • contains a list of controls and whether they are applicable or not
  • Certifying body: QMS Certification Services
  • Validity: July 2020 - July 2023
  • Use cases for Rocket.Chat users: due diligence, security review, regulatory compliance, internal audit, supply chain audit

Industry-specific resources

Cloud Security Alliance (CSA)

{% hint style="info" %} Scope: Hosted Offering {% endhint %}

Rocket.Chat has published a pre-filled questionnaire in the STAR-registry of the CSA here. The CSA is a leading organization in the standardization and improvement of security in cloud computing. The Consensus Assessments Initiative Questionnaire (CAIQ) is a self-assessment that is updated on an annual basis.

  • Name: Consensus Assessments Initiative Questionnaire
  • Last Update: October 2019
  • Use cases: due diligence, security review

Country-specific resources