ISO/IEC 15408 Compliance Statement
Common Criteria Security Alignment for RELIANOID Load Balancer and Organization
RELIANOID is aligned with the principles of ISO/IEC 15408, also known as the Common Criteria for Information Technology Security Evaluation (CC). This internationally recognized framework provides a structured approach for evaluating the security properties of information technology products.
While RELIANOID has not undergone formal certification under Common Criteria, our organizational controls and RELIANOID Load Balancer security practices incorporate security development, vulnerability management, testing, access control, network security, and operational processes that support alignment with Common Criteria security principles.
What is ISO/IEC 15408?
ISO/IEC 15408, commonly known as Common Criteria, provides a framework for evaluating the security properties of IT products through structured security requirements and assurance processes.
It is widely used in security evaluations for government, critical infrastructure, and other environments where structured product security assurance is required.
Product Security Scope
The RELIANOID security compliance scope includes the security controls and processes applied to the RELIANOID Load Balancer and its supporting development and operational environments.
These controls include:
- Secure Software Development Lifecycle (SSDLC)
- Automated security testing and vulnerability scanning
- Third-party library vulnerability monitoring
- Access control and multi-factor authentication
- Network and communications security
- Vulnerability management and remediation
- Security monitoring and incident response processes
Organizational Alignment with Common Criteria
RELIANOID follows security lifecycle and assurance principles across its internal development, deployment, and operational practices.
Security Risk Management
RELIANOID maintains an ICT and cyber risk register in which identified security risks are documented, assessed, assigned controls, and tracked through remediation plans.
The latest security review identified application security and vulnerability management findings that are tracked through the vulnerability management process and development sprint backlogs. Resolved findings are formally marked as resolved, while remaining findings are tracked through ongoing remediation activities.
Design and Development Controls
Our Secure Software Development Lifecycle (SSDLC) incorporates:
- Automated SAST/DAST security scanning on every product commit
- Weekly vulnerability scanning of third-party libraries
- Daily automated testing
- Continuous tracking of product test coverage
- Ongoing vulnerability identification and remediation
Security Functional Controls
RELIANOID maintains security controls supporting key areas relevant to Common Criteria-oriented product security assurance, including:
- Identification & Authentication: 100% of employee accounts are protected by multi-factor authentication.
- Access Control: Account lifecycle controls are maintained and no accounts requiring removal were identified in the latest review.
- Communications Protection: 100% of intra-service communications use private IPs and services support SSL/TLS.
- Network Protection: Network abuse IP protection and network DoS protection are implemented.
- Application Protection: Web Application Firewall (WAF) protection is implemented.
- Vulnerability Management: Product and service vulnerabilities are continuously identified, assessed, tracked, and remediated.
- Security Testing: Automated product testing is performed daily, with automated security scanning integrated into the development lifecycle.
Security Assurance and Testing
RELIANOID performs continuous security testing across its products and services.
The latest product vulnerability monitoring, dated 29 June 2026, reported 104 vulnerabilities fixed and 15 vulnerabilities remaining to fix.
Service and product pentesting and scanning conducted on 29 June 2026 launched 1,007 tests. Findings were classified according to risk level and tracked through remediation processes, with remediation review scheduled for 1 October 2026.
Development and Maintenance Processes
- SSDLC: Security is incorporated into the product development lifecycle through automated scanning and testing.
- Vulnerability Management: Third-party libraries are monitored through weekly vulnerability scans, while product vulnerabilities are tracked through formal vulnerability management processes.
- Automated Testing: Product automated tests are executed daily, with test coverage tracked for both Community and Enterprise editions.
- Release Security: Software updates are managed as part of the RELIANOID release process, with security updates communicated according to the established release timeline.
Operational Security
- Access Security: 100% of employee accounts are protected by MFA.
- Network Security: Private IPs are used for intra-service communications and SSL/TLS support is available across services.
- Abuse Protection: Network abuse IP protection and network DoS protection are implemented.
- Application Protection: Web Application Firewall protection is implemented.
- Incident Response: Incident response and reporting procedures are maintained, with incident review and near-miss processes in place.
- Backup and Restoration: Backup and restoration processes are tested quarterly.
Monitoring and Detection
RELIANOID maintains alert accuracy and escalation procedures and reviews incidents and near misses as part of its security monitoring and response processes.
Centralized log correlation through a Security Information and Event Management (SIEM) platform is currently planned as a future improvement. This roadmap item is intended to further strengthen centralized monitoring, correlation, and detection capabilities.
Use in Regulated and High-Assurance Environments
While RELIANOID is not formally certified under ISO/IEC 15408, our security practices support customers performing security and procurement assessments in regulated and security-sensitive environments.
RELIANOID can provide supporting security and compliance documentation, including information concerning:
- Product security controls
- Vulnerability management and remediation
- Security testing and pentesting
- Secure development lifecycle practices
- Access and network security controls
- Organizational security and risk management
Assurance Measures and Evidence
To support Common Criteria-aligned assurance and customer security assessments, RELIANOID maintains documented evidence relating to:
- Security and compliance risk management
- Vulnerability monitoring and remediation
- Product and service security testing
- Secure software development lifecycle controls
- Automated security testing and third-party library monitoring
- Access control and network security practices
Organizational Alignment
- Security Governance: RELIANOID maintains documented security policies, risk management processes, and compliance alignments across its organizational operations.
- Security Awareness: Security awareness training is provided, completion is tracked, and training content is updated.
- Incident Management: Incident response and reporting procedures are maintained, with incident reviews and near-miss processes in place.
- Policies: RELIANOID maintains policies covering Business Continuity and Disaster Recovery, Data Protection, Incident Response, Third-Party Risk Management, Service Level Management, and other security-related areas.
Supporting Evidence
- Latest RELIANOID Security Report: The latest Security Compliance Report provides current information on security controls, risks, vulnerability management, testing, and compliance alignment.
- Security and Compliance Documentation: RELIANOID maintains documentation supporting customer security assessments and compliance reviews.
- Customer Assurance Statements: RELIANOID provides security and compliance information to support customer assessments in regulated and security-sensitive environments.
Commitment to Common Criteria Principles
RELIANOID is committed to:
- Continuously improving product security and secure development practices
- Maintaining structured vulnerability management and remediation processes
- Expanding automated security testing and monitoring capabilities
- Supporting customer-led security and procurement evaluations
- Maintaining transparency through security and compliance documentation
- Strengthening security controls throughout the product lifecycle
Document Reviews
| Date |
Comment |
| 10th July 2025 |
Initial publication of ISO/IEC 15408 compliance alignment |
| 2nd September 2025 |
Expanded TOE scope, updated SFR mapping, SAR alignment, SSDLC and Ops details, organizational governance, and supporting evidence |
| 30th June 2026 |
Security and compliance review updated based on the RELIANOID Security Compliance Report 2026Q2 |
Contact and Assurance
We welcome requests for technical evaluation materials, security control documentation, or support for Common Criteria-related procurement and security assessment projects.
Contact our Compliance & Security Team
Download Latest Security Report