Red Hat Ansible Automation Platform Trust Center

Trust center

Red Hat operates a corporate trust surface and a product compliance catalog covering the portfolio that Ansible Automation Platform belongs to. There is no AAP-specific trust portal; these are Red Hat programs AAP inherits.

Red Hat Ansible Automation Platform maintains a public trust center documenting Common Criteria, FIPS 140, ISO/IEC 27001, ISO/IEC 27018, ISO 42001, ISO/SAE 21434, DISA STIG, HIPAA, HDS, CIS Benchmarks, BSI, CCN-STIC / ENS, EU Cyber Resilience Act, EU AI Act, and Accessibility Conformance Reports (VPAT) compliance.

AutomationConfiguration ManagementDevOpsEnterpriseRed HatAnsibleIT OperationsEvent-Driven ArchitectureInfrastructure as CodeMCP
Trust center:

Certifications & Compliance

Common CriteriaFIPS 140ISO/IEC 27001ISO/IEC 27018ISO 42001ISO/SAE 21434DISA STIGHIPAAHDSCIS BenchmarksBSICCN-STIC / ENSEU Cyber Resilience ActEU AI ActAccessibility Conformance Reports (VPAT)

Source

Trust Center

Raw ↑
generated: '2026-08-29'
method: searched
source: https://www.redhat.com/en/trust and https://access.redhat.com/compliance
description: >-
  Red Hat operates a corporate trust surface and a product compliance catalog covering the
  portfolio that Ansible Automation Platform belongs to. There is no AAP-specific trust portal;
  these are Red Hat programs AAP inherits.
trust_center:
  url: https://www.redhat.com/en/trust
  status: 200
  hosted_by: self
product_compliance_catalog:
  url: https://access.redhat.com/compliance
  status: 200
  aap_entries: >-
    The catalog's own product filter lists 9 compliance items under "Red Hat Ansible Automation
    Platform Service on AWS".
certifications:
- name: Common Criteria
- name: FIPS 140
- name: ISO/IEC 27001
- name: ISO/IEC 27018
- name: ISO 42001
  note: AI management system
- name: ISO/SAE 21434
  note: automotive cybersecurity engineering
- name: DISA STIG
- name: HIPAA
- name: HDS
  note: French health data hosting
- name: CIS Benchmarks
- name: BSI
- name: CCN-STIC / ENS
  note: Spanish national security framework
- name: EU Cyber Resilience Act
- name: EU AI Act
- name: Accessibility Conformance Reports (VPAT)
security_program:
  disclosure_policy: https://access.redhat.com/security/team/contact/
  contact: secalert@redhat.com
  security_txt: https://www.redhat.com/.well-known/security.txt
  acknowledgments: https://access.redhat.com/articles/66234
  encryption_key: https://security.access.redhat.com/data/97f5eac4.txt
  cve_numbering_authority: true
  csaf_vex_feed: https://security.access.redhat.com/data/csaf/v2/provider-metadata.json
  security_data_api: https://access.redhat.com/hydra/rest/securitydata/csaf.json
  bug_bounty: none published
  rfc2350: https://www.redhat.com/en/trust/RFC-2350
evidence:
- url: https://www.redhat.com/en/trust
  status: 200
- url: https://access.redhat.com/compliance
  status: 200
- url: https://www.redhat.com/.well-known/security.txt
  status: 200
- url: https://access.redhat.com/hydra/rest/securitydata/csaf.json?package=automation-controller
  status: 200
- url: https://access.redhat.com/security/team/contact/
  status: 200

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/red-hat-ansible-automation-platform-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.