Skip to main content

Compliance

OASIS maintains implementation evidence for security, privacy, accessibility, records, and AI-governance controls. Independent attestation status is listed below.

Reviewed September 15, 2026

Control details

SOC 2

  • Status: roadmap.
  • Controls are being mapped to the AICPA Trust Services Criteria with owners, review cadence, and evidence references.
  • Certification has not been obtained.

ISO/IEC 27001

  • Status: roadmap.
  • Policies and implementation evidence are being mapped to Annex A controls.
  • Certification has not been obtained.

HECVAT

  • An evidence workspace and response-preparation checklist are maintained for higher-education diligence.
  • A completed response is available through procurement review when applicable.

VPAT / ACR

  • Preparation in progress.
  • Accessibility evidence, source-level checks, and remediation records are maintained; OASIS does not present a completed public ACR as of this review.

Records governance

  • The product supports tenant schedules, legal holds, disposition review, custody-aware export, immutable issued reports, and evidence checksums.

Evidence review

  • Qualified buyers may request architecture, access, retention, incident-response, accessibility, and implementation evidence under appropriate confidentiality terms.

Important: OASIS does not claim FedRAMP authorization, SOC 2 certification, ISO/IEC 27001 certification, or a completed VPAT/ACR on this page.