Resources
ISO/IEC 42001:2023
AI Management Systems Independent certification of Maven's AI Management System, validating governance controls for responsible AI development and deployment, including AI risk assessment, bias monitoring, transparency, human oversight, and continuous improvement of AI systems.
ISO/IEC 27701:2019
Privacy Information Management Independent certification extending Maven's ISMS to include a Privacy Information Management System (PIMS), validating controls for the processing and protection of personally identifiable information (PII) in alignment with GDPR, CCPA, and other global privacy regulations.
PCI-DSS 4.0 – Attestation of Compliance (AOC)
This PCI-DSS 4.0 AOC certifies our compliance with Level 1 requirements. Valid through May 23, 2026.
ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019
ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019 – Information Security, Cloud Security, and Cloud Privacy Independent certification of Maven's integrated Information Security Management System (ISMS) covering information security management (27001), cloud-specific security controls including shared responsibility, tenant isolation, and cloud service administration (27017), and protection of personally identifiable information in public cloud environments including consent management, data minimization, and transparency (27018).
HIPAA + HITECH + SOC2 Type II (2025)
Final Report includes an Attestation of SOC 2 Type II, HIPAA, and HITECH Assessments, validating compliance with SOC 2 security, availability, and confidentiality criteria, as well as HIPAA Security and Privacy Rule requirements and the HITECH Act’s enhanced privacy and security provisions.
Penetration Test Summary (2025)
External Penetration Test: Independent security assessment aligned with the highest industry standards, including PCI-DSS ROC 4.0, to identify vulnerabilities and validate system controls.
Technical and Organizational Measures
Summary of security, privacy, and operational controls implemented to protect data and ensure regulatory compliance.
Data Processing Addendum
Contractual terms defining data privacy, security, and processing obligations in accordance with applicable laws and customer requirements.
SOC 2 Type II (2024)
Independent assessment report on the design and operating effectiveness of security, availability, and confidentiality controls.