# Akka Trust Center > Akka is a technology company providing the Akka platform for reactive microservices, distributed systems, and agentic AI applications. This file summarises Akka's publicly available security, compliance, and trust information for use by AI tools and agents. Security contact: security@akka.io InfoSec contact: infosec@akka.io Privacy policy: https://akka.io/legal/privacy Trust center: https://trust.akka.io ## Compliance Frameworks Akka maintains attestation or certification against the following active compliance frameworks: - [AICPA System Organization and Controls 2](https://trust.akka.io/soc3) - [AWS Agentic Scoping Framework](https://trust.akka.io/aws-asf) - [Akka's Internal Assurance Framework](https://trust.akka.io/internal) - [Australia - Operational Risk Management](https://trust.akka.io/apra-cps-230) - [Australia — Information Security for APRA-regulated entities](https://trust.akka.io/apra-cps-234) - [Australian Privacy Act/Australian Privacy Principles](https://trust.akka.io/app) - [Brazil Artificial Intelligence Bill (PL 2338/2023)](https://trust.akka.io/brazil-ai) - [Business Continuity Standard](https://trust.akka.io/iso-22301) - [CSA's Agentic Trust Framework](https://trust.akka.io/csa-atf) - [California Consumer Protection Act](https://trust.akka.io/ccpa) - [Canada's Personal Information Protection and Electronic Documents Act (PIPEDA)](https://trust.akka.io/canada-pipeda) - [Cloud Security Alliance Security, Trust and Assurance Registry](https://trust.akka.io/csa-star) - [Code of Practice for Information Security Controls Based On ISO/IEC 27002 for Cloud Services](https://trust.akka.io/iso-iec-27017) - [Code of Practice for Protection of Personally Identifiable Information (PII) In Public Clouds Acting As PII Processors](https://trust.akka.io/iso-iec-27018) - [Controls for Customer Contractual Obligations](https://trust.akka.io/customer) - [EBA Guidelines on ICT and Security Risk Management](https://trust.akka.io/eba-ict) - [ENISA European Union Common Criteria for Cybersecurity Certification](https://trust.akka.io/eucc) - [EU Artificial Intelligence Act](https://trust.akka.io/eu-ai) - [EU Cyber Resilience Act](https://trust.akka.io/eu-cra) - [EU Data Act](https://trust.akka.io/eu-da) - [EU General Data Protection Regulation](https://trust.akka.io/eu-gdpr) - [EU-US Data Privacy Framework](https://trust.akka.io/eu-us-dpf) - [European Union's Digital Operational Resilience Act](https://trust.akka.io/eu-dora) - [G7 Hiroshima AI Process Code of Conduct](https://trust.akka.io/g7-hiroshima-ai) - [Health Insurance Portability and Accountability Act](https://trust.akka.io/hipaa) - [Hong Kong Monetary Authority Generative AI Guidance](https://trust.akka.io/hk-hkma-genai) - [ISO/IEC 27001/27002: Information Security, Cybersecurity and Privacy Protection - Information Security Controls](https://trust.akka.io/iso-27001) - [ISO/IEC 42001: Artificial intelligence Management System](https://trust.akka.io/iso-iec-42001) - [Impact Assessments Guidance for AI systems](https://trust.akka.io/iso-iec-42005) - [India Digital Personal Data Protection Act 2023](https://trust.akka.io/india-dpdp) - [Information Technology — Artificial Intelligence — Guidance on Risk Management](https://trust.akka.io/iso-iec-23894) - [Information technology – Artificial intelligence – Overview of trustworthiness in artificial intelligence:](https://trust.akka.io/iso-iec-24028) - [Japan Act on the Protection of Personal Information (APPI)](https://trust.akka.io/japan-appi) - [Monetary Authority of Singapore — Technology Risk Management Guidelines](https://trust.akka.io/singapore-mas-trm) - [NIST CyberSecurity Framework 2.0](https://trust.akka.io/nist-csf) - [NIST Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations](https://trust.akka.io/nist-sp-800-161) - [NIST SP AI 100-1 NIST AI Risk Management Framework ](https://trust.akka.io/nist-ai-rmf-1-0) - [Network and Information Security Directive 2](https://trust.akka.io/nis2) - [OECD Principles on Artificial Intelligence](https://trust.akka.io/oecd-ai) - [OSFI/FCAC AI Report](https://trust.akka.io/osfi-fcac) - [OWASP AI Exchange](https://trust.akka.io/owasp-ai-exchange) - [OWASP AI Security and LLM Security Guidelines](https://trust.akka.io/owasp-ai) - [Payment Card Industry Data Security Standard](https://trust.akka.io/pci-dss) - [Security Techniques - Extension ISO/IEC 27001 and ISO/IEC 27002 For Privacy Information Management - Requirements and Guidelines](https://trust.akka.io/iso-iec-27701) - [Singapore Personal Data Protection Act 2012 (PDPA)](https://trust.akka.io/singapore-pdpa) - [Singapore's Model Governance Framework for Agentic AI](https://trust.akka.io/mgf-aai) - [Trusted Technology Alliance](https://trust.akka.io/tta) - [Trustworthy and Responsible AI: Artificial Intelligence Risk Management: Framework: Generative Artificial Intelligence Profile](https://trust.akka.io/nist-ai-600-1) - [Turkey Law on Protection of Personal Data (KVKK) No. 6698](https://trust.akka.io/turkey-kvkk) - [U.S. Treasury Department: Office of Foreign Assets Control: Sanctions Program](https://trust.akka.io/ofac) - [UK DSIT AI Governance Code of Practice](https://trust.akka.io/uk-dsit-ai-code) - [UK FCA/PRA Operational Resilience](https://trust.akka.io/uk-fca-pra) - [UK General Data Protection Regulation](https://trust.akka.io/uk-gdpr) ## Policies The following information security policies are publicly available: - [Akka Availability Guarantee Policy](https://trust.akka.io/availability-guarantee) - [Akka Federation Plane SLA Policy](https://trust.akka.io/cloud-services-sla) - [Backup and Restoration Policy](https://trust.akka.io/backup-restoration) - [Cloud Terms of Service](https://trust.akka.io/cloud-terms-of-service) - [Customer Support Policy](https://trust.akka.io/customer-support) - [Privacy Policy](https://trust.akka.io/privacy) - [Resilience Guarantee Policy](https://trust.akka.io/resilience-guarantee) - [Terms of Use](https://trust.akka.io/terms-of-use) ## Resources The following resources are publicly available: ### AI - [Trustworthy AI with Akka](https://trust.akka.io/ai) ### Information Security and Compliance - [SOC2 Type III (SOC3) Report](https://trust.akka.io/soc3) - [SBOM by License](https://trust.akka.io/sbom-by-license) - [SBOM by Module](https://trust.akka.io/sbom-by-module) ## Key Facts - Akka is an ISO 27001 certified and SOC 2 Type II attested software company. - Akka's products have never experienced a security breach. - Akka provides the Akka platform for building resilient, distributed, and agentic AI applications. - Security vulnerability disclosures: security@akka.io - Security announcements: https://doc.akka.io/reference/security-announcements/ - Akka documentation: https://doc.akka.io