Rhombus Systems · Trust Center

Rhombus Systems Trust Center

Trust center

Rhombus Systems maintains a public trust center documenting SOC 2, GDPR, HIPAA, PCI, BIPA, PIPEDA, CMMC, NIST, CJIS, NDAA, and TAA compliance.

Physical SecurityVideo SurveillanceAccess ControlIoT SensorsCloud Video ManagementAlarm MonitoringComputer VisionBuilding ManagementSecurity CamerasCompany
Trust center: https://www.rhombus.com/trust/

Certifications & Compliance

SOC 2GDPRHIPAAPCIBIPAPIPEDACMMCNISTCJISNDAATAA

Source

Trust Center

Raw ↑
generated: '2026-08-26'
method: searched
source: https://www.rhombus.com/trust/
url: https://www.rhombus.com/trust/
status: 200
portal: false
portal_note: >-
  This is a marketing trust PAGE, not a trust portal. There is no Vanta/Drata/SafeBase-style
  portal, no downloadable or request-gated report flow, no subprocessor list, and no audit
  period or Type designation. security.txt names this same URL as its Policy.
certifications:
- name: SOC 2
  type: null
  claim: Security compliance and adherence to SOC2 standards to ensure data security
  report_available: false
  note: No Type I / Type II designation and no audit period published.
- name: GDPR
  claim: Stay in full compliance with GDPR data processing agreements
- name: HIPAA
  claim: Maintain HIPAA compliance using Rhombus as a tool to ensure the protection of PHI
- name: PCI
  claim: Meet PCI standards by protecting cardholder data and sensitive authentication data
- name: BIPA
  claim: Comply with BIPA regarding the collection and storage of biometric information
  note: >-
    Material for this provider specifically — Rhombus ships face recognition
    (Face Recognition Matchmaker / Person / Event webservices, 21 operations) and BIPA governs
    biometric identifiers.
- name: PIPEDA
  claim: Meet PIPEDA regulations on how businesses collect, use, and disclose such data
- name: CMMC
  claim: Comply with DoD cybersecurity standards for defense industrial base (DIB) contractors
- name: NIST
  claim: Comply with the strictest cybersecurity & data privacy standards in the US
- name: CJIS
  claim: Adhere to standards set by criminal justice and law enforcement for securing CJI data
- name: NDAA
  claim: All hardware procured from white-listed manufacturers for cybersecurity purposes
  category: hardware supply chain
- name: TAA
  claim: Hardware sourced exclusively from white-listed countries for cybersecurity purposes
  category: hardware supply chain
security_claims:
- End-to-end encryption across media, video, and cloud communication
- Automatic security updates with firmware deployment and health monitoring
- In-house hardware engineering with up to a 10-year warranty
vulnerability_disclosure:
  program: true
  detail: security/rhombus-systems-vulnerability-disclosure.yml
  contact: mailto:security@rhombussystems.com
  policy: https://www.rhombus.com/trust/
  bug_bounty: false
  bug_bounty_note: >-
    No HackerOne, Bugcrowd or Intigriti program was found. Disclosure is via the security.txt
    contact address only.
  penetration_testing_statement: false
gaps:
- No SOC 2 Type designation, audit period, or auditor named.
- No report request or NDA flow — a buyer cannot obtain evidence from the public surface.
- No subprocessor list and no data-residency page, despite the API offering a distinct EU region.
- No published penetration-testing cadence.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/rhombus-systems-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.