Sanctum SecOps
Trust Center

How We Secure Ourselves

Our own control posture, published. If we would not run it internally, we will not sell it to you.


FIPS 140-3

FIPS Baseline

AES-256-GCM, SHA-2 family, HMAC-SHA-2, ECDSA P-256 and P-384, RSA-3072 or greater, TLS 1.3 only.

FIPS 203/204

Post-Quantum Readiness

ML-KEM key establishment and ML-DSA signing per FIPS 203 and 204, deployed in approved hybrid modes.

Zero ports

No Inbound Exposure

Every internal service is fronted by an identity-aware tunnel. The origin has no public listener.

Published

Subprocessors

A current register of every subprocessor with data category and hosting region.

Questions on any control receive a written answer, not a deflection. Zone sanctumsecops.com. Gate open.