Continuous monitoring
Automated checks connect current operational proof to the controls they support and identify stale or missing evidence.
Trust Center
Security, privacy, and compliance
Resgrid protects the teams who depend on us with continuously evaluated controls, governed policies, transparent service-provider practices, and a security program designed to produce evidence—not promises.
Assurance by design
Automated checks connect current operational proof to the controls they support and identify stale or missing evidence.
See implementation and monitoring coverage without exposing sensitive systems, raw evidence, or internal security details.
Published policies are immutable, system-generated PDFs tied to the exact approved revision and its framework mappings.
Approved visitors can review restricted reports and accept version-bound confidentiality terms through the Trust Console.
Published subprocessors explain who supports the service, what they do, where they operate, and their privacy commitments.
Security updates, published incident notices, insurance statements, and current assurance material stay in one reviewable place.
Security you can evaluate
A certification badge or a one-time questionnaire can only tell part of the story. Resgrid connects governed policy, current control posture, responsible disclosure, service-provider transparency, and customer-ready assurance in one reviewable program.
Operational evidence is evaluated continuously, so gaps remain visible instead of disappearing behind an annual point-in-time review.
Published policies map to the controls and frameworks they support, giving buyers a clear path from commitment to implementation.
Subprocessors, security updates, incident notices, and recognized researchers can be reviewed without exposing raw evidence or sensitive systems.
Compliance program
One common-control system maps Resgrid's policies and technical proof across the requirements that matter to customers, regulated organizations, and public-sector teams.
Resgrid-authored readiness summaries for consumer rights notices preferences risk assessments cybersecurity audits and ADMT. Applicability thresholds exemptions phased dates and filings require an approved current California profile.
Version California law through 2026 readiness profileReadiness projection by public NIST control family with Low or Moderate profile selection and OSCAL draft exports. The exact current FedRAMP baseline tailoring parameters templates sponsor assessment and authorization decision remain authoritative external outcomes.
Version NIST SP 800-53 Release 5.2.0 and SP 800-53B Rev 5 baselinesResgrid-authored accountability summaries keyed to the official EUR-Lex regulation. Applicability controller or processor role Member State law and legal conclusions remain governed profile decisions.
Version Regulation EU 2016/679Resgrid-authored readiness summaries keyed to public HHS rule sections. The 2025 Security Rule proposal is not treated as final. Regulated-entity status and legal interpretation require an approved applicability profile.
Version 45 CFR Parts 160 and 164 current-rule readiness profileNo proprietary HITRUST requirement statements are redistributed. This pack supplies governance gates for referencing an operator licensed MyCSF assessment version scope maturity evidence and assessor workflow.
Version Licensed MyCSF profile selected by the operatorResgrid-authored readiness summaries for all 93 Annex A control references, grouped into organizational, people, physical, and technological themes. Consult licensed ISO/IEC 27001 and 27002 material for authoritative wording and implementation guidance.
Version 2022 Annex AResgrid-authored readiness summaries for the PCI DSS 4.0 requirements, organised by requirement group. Applicability is conditional - PCI DSS applies only where account data is stored, processed, or transmitted, so scope the cardholder data environment before treating this projection as an obligation. Requirements that depend on a Qualified Security Assessor, an Approved Scanning Vendor, or an acquirer decision are readiness projections only; the assessment outcome remains an external authoritative result. Consult the PCI Security Standards Council for authoritative requirement and testing-procedure wording.
Version v4.0.1Resgrid-authored readiness summaries for the AICPA Trust Services Criteria. Security common criteria are enabled by default; availability, processing integrity, confidentiality, and privacy criteria are marked optional until scoped. Consult licensed AICPA material for authoritative wording.
Version 2017 criteria with 2022 revised points of focusResponsible disclosure
We thank the independent security researchers who responsibly report valid vulnerabilities and help make Resgrid safer for every team.
Recognized responsible-disclosure contributors will appear here.