Lightbend · Trust Center

Lightbend Trust Center

Trust center

Lightbend maintains a public trust center documenting SOC 2 Type II, SOC 3 (SOC 2 Type III), ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27018, ISO/IEC 22301, ISO/IEC 42001, ISO/IEC 42005, ISO/IEC 23894, ISO/IEC 24028, CSA STAR, PCI DSS, HIPAA, GDPR, UK GDPR, CCPA, EU-US Data Privacy Framework, EU Artificial Intelligence Act, NIST Cybersecurity Framework 2.0, NIST AI Risk Management Framework (SP AI 100-1), NIST SP 800-161, NIS2, DORA, EU Cyber Resilience Act, EU Data Act, ENISA EUCC, EBA Guidelines on ICT and Security Risk Management, PIPEDA, APPI, PDPA (Singapore), Australia Privacy Act / APPs, UK DSIT AI Governance Code of Practice, CSA Agentic Trust Framework, Trusted Technology Alliance, and OFAC Sanctions Program compliance.

CompanyAi InfrastructureAgentic AiActor ModelDistributed SystemsReactiveJavaScalaOrchestrationAi Governance
Trust center: https://trust.akka.io/

Certifications & Compliance

SOC 2 Type IISOC 3 (SOC 2 Type III)ISO/IEC 27001ISO/IEC 27002ISO/IEC 27018ISO/IEC 22301ISO/IEC 42001ISO/IEC 42005ISO/IEC 23894ISO/IEC 24028CSA STARPCI DSSHIPAAGDPRUK GDPRCCPAEU-US Data Privacy FrameworkEU Artificial Intelligence ActNIST Cybersecurity Framework 2.0NIST AI Risk Management Framework (SP AI 100-1)NIST SP 800-161NIS2DORAEU Cyber Resilience ActEU Data ActENISA EUCCEBA Guidelines on ICT and Security Risk ManagementPIPEDAAPPIPDPA (Singapore)Australia Privacy Act / APPsUK DSIT AI Governance Code of PracticeCSA Agentic Trust FrameworkTrusted Technology AllianceOFAC Sanctions Program

Source

Trust Center

lightbend-trust-center.yml Raw ↑
generated: '2026-07-19'
method: searched
source: https://trust.akka.io/
url: https://trust.akka.io/
notes: >-
  Lightbend (dba Akka) publishes a public trust center at trust.akka.io covering security, privacy, AI governance and
  resilience posture. SOC 2 Type III (SOC 3) is published publicly; SOC 2 Type II and the penetration test report are
  available on request via infosec@akka.io.
certifications:
  - SOC 2 Type II
  - SOC 3 (SOC 2 Type III)
  - ISO/IEC 27001
  - ISO/IEC 27002
  - ISO/IEC 27018
  - ISO/IEC 22301
  - ISO/IEC 42001
  - ISO/IEC 42005
  - ISO/IEC 23894
  - ISO/IEC 24028
  - CSA STAR
  - PCI DSS
  - HIPAA
  - GDPR
  - UK GDPR
  - CCPA
  - EU-US Data Privacy Framework
  - EU Artificial Intelligence Act
  - NIST Cybersecurity Framework 2.0
  - NIST AI Risk Management Framework (SP AI 100-1)
  - NIST SP 800-161
  - NIS2
  - DORA
  - EU Cyber Resilience Act
  - EU Data Act
  - ENISA EUCC
  - EBA Guidelines on ICT and Security Risk Management
  - PIPEDA
  - APPI
  - PDPA (Singapore)
  - Australia Privacy Act / APPs
  - UK DSIT AI Governance Code of Practice
  - CSA Agentic Trust Framework
  - Trusted Technology Alliance
  - OFAC Sanctions Program
public_reports:
  - name: SOC 3 report
    url: https://trust.akka.io/soc3
  - name: SBOM by module
  - name: SBOM by license
  - name: Trustworthy AI with Akka
reports_on_request:
  contact: infosec@akka.io
  items:
    - SOC 2 Type II report
    - Penetration test report
    - Akka 2025 Information Security Program Overview
    - Akka Partner Compliance and Security Practices
    - Developing Secure Apps with Akka
    - Akka BYOC Trust Policies
    - AAO Data Flows and Security Pathways
    - BYOC architecture documentation
    - AAO RACI matrices (BYOK and BYOC)
guarantees:
  - name: Availability guarantee
    url: https://trust.akka.io/availability-guarantee
  - name: Resilience guarantee
    url: https://trust.akka.io/resilience-guarantee
  - name: SLA service credits
    detail: Up to 25% credit for uptime below 99.00% or latency percentile drops below 80%.
subprocessors:
  - Amazon
  - Google
  - Microsoft
  - Cloudsmith
  - Docebo
  - Zoho
  - HubSpot
  - Salesforce