Rhombus Systems · Trust Center

Rhombus Systems Trust Center

Trust center

Rhombus Systems maintains a public trust center documenting SOC 2, GDPR, HIPAA, PCI, BIPA, PIPEDA, CMMC, NIST, CJIS, NDAA, and TAA compliance.

Physical SecurityVideo SurveillanceAccess ControlIoT SensorsCloud Video ManagementAlarm MonitoringComputer-VisionBuilding ManagementSecurity CamerasCompany
Trust center: https://www.rhombus.com/trust/

Certifications & Compliance

SOC 2GDPRHIPAAPCIBIPAPIPEDACMMCNISTCJISNDAATAA

Source

Trust Center

Raw ↑
generated: '2026-08-26'
method: searched
source: https://www.rhombus.com/trust/
url: https://www.rhombus.com/trust/
status: 200
portal: false
portal_note: >-
  This is a marketing trust PAGE, not a trust portal. There is no Vanta/Drata/SafeBase-style
  portal, no downloadable or request-gated report flow, no subprocessor list, and no audit
  period or Type designation. security.txt names this same URL as its Policy.
certifications:
- name: SOC 2
  type: null
  claim: Security compliance and adherence to SOC2 standards to ensure data security
  report_available: false
  note: No Type I / Type II designation and no audit period published.
- name: GDPR
  claim: Stay in full compliance with GDPR data processing agreements
- name: HIPAA
  claim: Maintain HIPAA compliance using Rhombus as a tool to ensure the protection of PHI
- name: PCI
  claim: Meet PCI standards by protecting cardholder data and sensitive authentication data
- name: BIPA
  claim: Comply with BIPA regarding the collection and storage of biometric information
  note: >-
    Material for this provider specifically — Rhombus ships face recognition
    (Face Recognition Matchmaker / Person / Event webservices, 21 operations) and BIPA governs
    biometric identifiers.
- name: PIPEDA
  claim: Meet PIPEDA regulations on how businesses collect, use, and disclose such data
- name: CMMC
  claim: Comply with DoD cybersecurity standards for defense industrial base (DIB) contractors
- name: NIST
  claim: Comply with the strictest cybersecurity & data privacy standards in the US
- name: CJIS
  claim: Adhere to standards set by criminal justice and law enforcement for securing CJI data
- name: NDAA
  claim: All hardware procured from white-listed manufacturers for cybersecurity purposes
  category: hardware supply chain
- name: TAA
  claim: Hardware sourced exclusively from white-listed countries for cybersecurity purposes
  category: hardware supply chain
security_claims:
- End-to-end encryption across media, video, and cloud communication
- Automatic security updates with firmware deployment and health monitoring
- In-house hardware engineering with up to a 10-year warranty
vulnerability_disclosure:
  program: true
  detail: security/rhombus-systems-vulnerability-disclosure.yml
  contact: mailto:security@rhombussystems.com
  policy: https://www.rhombus.com/trust/
  bug_bounty: false
  bug_bounty_note: >-
    No HackerOne, Bugcrowd or Intigriti program was found. Disclosure is via the security.txt
    contact address only.
  penetration_testing_statement: false
gaps:
- No SOC 2 Type designation, audit period, or auditor named.
- No report request or NDA flow — a buyer cannot obtain evidence from the public surface.
- No subprocessor list and no data-residency page, despite the API offering a distinct EU region.
- No published penetration-testing cadence.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/rhombus-systems-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.