ISO/IEC 27034 Compliance Statement
Application Security Alignment for RELIANOID Load Balancer and Organizational Practices
At RELIANOID, security is engineered into every phase of our product and operations. We are aligned with the principles and processes of ISO/IEC 27034 (Application Security), integrating security requirements, validation, and governance across the full application lifecycle of the RELIANOID Load Balancer and our supporting services.
While RELIANOID is not certified under ISO/IEC 27034, our policies, controls, and technical measures are mapped to its Application Security Management Process (ASMP) to help customers in regulated sectors—including finance, healthcare, government, and enterprise—achieve secure-by-design deployments across on-premises and cloud environments.
The latest RELIANOID Security Compliance Report 2026Q2 confirms that ISO/IEC 27034 remains a current security compliance alignment, with an annual review cycle.
Company & Organizational Context
- Legal Entities: RELIANOID LLC (New Mexico, USA) and RELIANOID SL (Spain, EU)
- Industries Served: Telco, Healthcare, Public Sector, Finance among others
- Key Markets: USA and Europe, with strong focus on regulatory compliance
- Governance: Security compliance is overseen by our CEO, CTO, and COO together with the compliance team to ensure robust organizational and product-level security
The 2026Q2 security assessment further confirms an active ICT and cyber risk register covering application security and vulnerability management risks. Identified findings are documented in the vulnerability tracker and managed through remediation plans and development sprint backlogs.
Scope of Alignment
Our alignment encompasses:
- Platform: RELIANOID Load Balancer (on-prem, private/public cloud, hybrid)
- Processes: Secure software development, testing, release, deployment, and support
- Organization: Security governance, risk management, third-party oversight, and incident response
The latest security assessment confirms that application security controls are implemented across both RELIANOID services and the product, with specific controls and maturity levels tracked separately for each environment.
Application Security Governance (ASMP)
We apply ISO/IEC 27034’s governance concepts to ensure consistent, auditable application security:
Policy & Risk Management
- Documented application security policies maintained in internal wiki with automatic version control and reviewed after each release
- Security requirements tracked via issues in our Gitea platform, raised by clients, internal teams, or pre-sales requests
- Lifecycle risk assessments through functional, integration, and platform-level testing
The current ICT and cyber risk register demonstrates ongoing application security risk management. During the latest review:
- Six medium-risk pentesting issues were resolved.
- 18 low-risk vulnerabilities identified in the latest scan were resolved.
- Two vulnerabilities across systems and components were resolved.
- Three high-risk pentesting issues were resolved.
- One high-risk issue and 11 medium-risk issues remain in progress within the 2026Q3 sprint backlog.
- Additional deep scanning is being incorporated into the improvement backlog.
Roles, Responsibilities & Shared Responsibility
- Defined ownership across product, engineering, security, and operations
- Clear shared responsibility guidance for customers in cloud and on-prem deployments
- Leverage open source components enabling public audits, code reviews, and improved supply chain security
Secure Development Lifecycle (SSDLC)
RELIANOID embeds security into design, build, and release:
- Secure design reviews, brainstorming, and threat modeling with focus on availability, scalability, and usability
- Automated SAST (perlcritic scripts integrated with CI/CD), DAST (online pentesting tools), and quarterly reports with improvements
- Dependency management via GPG official repositories to ensure software authenticity
- Compliance with OWASP ASVS and CERT secure coding standards
- Dedicated local, organizational, and preproduction environments separated from production
The latest Security Compliance Report confirms that SSDLC enforcement is implemented for both RELIANOID services and product development. For the product, automated SAST/DAST scanning is performed on every commit, third-party libraries undergo weekly vulnerability scanning, and automated tests run daily.
For services, SSDLC enforcement is also confirmed. The latest report separately identifies automated SAST/DAST scanning for services as a planned improvement, while network abuse IP protection, network DoS protection, WAF protection, and third-party library vulnerability controls are already implemented.
Application Security Testing Coverage
The latest product security assessment reports daily automated testing with coverage tracked separately for the Community and Enterprise editions:
- Community Edition: 102/159 tracked test coverage indicators.
- Enterprise Edition: 267/376 tracked test coverage indicators.
Security Functional Controls
The platform includes:
- Access control: RBAC, SSO, LDAP, and Active Directory integrations
- Authentication: MFA portals integrated with RADIUS, LDAP, AD, Google Captcha v2, and TOTP apps
- Cryptography: TLS v1.2 and v1.3, at-rest encryption, customer-managed keys, and strong SSL ciphers by default
- Auditability: Log retention for 7 days, multiple log levels, and SIEM integration
- Security modules (IPDS): Blacklists/Whitelists (preloaded, geolocated, and custom), DNS-BL (RBL), DDoS protection (rate limiting, SYN/RST/TCP filters), Web Application Firewall (OWASP CRS and custom rules)
- Configuration security: Secure defaults and least-privilege measures embedded by design
The 2026Q2 Security Compliance Report adds the following current control measurements:
- MFA: 100% of employee accounts are protected by multi-factor enforcement.
- Account Lifecycle: No accounts were identified as requiring removal during the assessment.
- Network Protection: 100% of intra-service communications use private IPs.
- SSL/TLS: 100% of assessed services support SSL/TLS.
- Network Abuse Protection: Implemented.
- Network DoS Protection: Implemented.
- Web Application Firewall: Implemented.
- Third-Party Library Security: Vulnerability monitoring is implemented.
Encryption clarification: The existing product description above is retained as originally published. The latest 2026Q2 security report specifically records encryption of data at rest and in transit as a control, with the current implementation noted as encryption in transit.
Application Security Verification & Testing
- Internal penetration tests conducted twice per quarter
- External assessments executed by independent testers under RELIANOID’s oversight
- Vulnerability remediation SLA: Critical < 24h, Medium < 7 days, Low < 30 days
- Currently aligning with ISO/IEC 27001, SOC 2, and other security standards
The latest 2026Q2 security testing provides additional evidence of continuous verification:
- Product vulnerability monitoring: 104 vulnerabilities fixed and 15 vulnerabilities remaining to fix as of 29 June 2026.
- Service and product pentesting: 1,007 tests launched as of 29 June 2026.
- Critical findings: 0.
- High findings: 16, with 15 identified as false positives.
- Medium findings: 12, with one identified as a false positive.
- Low findings: 43.
- Informational findings: 89.
- Remediation review: Findings are scheduled for review on 1 October 2026.
Operational Security & Monitoring
- Change and release management follows 3-month iteration cycles (Community and Enterprise Editions)
- Incident response via Customer Portal → Gitea escalation → hotfix deployment after QA validation
- Monitoring includes external vulnerability feeds, zero-day detection, and in-house infrastructure monitoring
- Secure provisioning and decommissioning with automated Ansible workflows
The current security report confirms:
- Service uptime: Last 30-days services uptime was 99.934%.
- Alerting: Alert accuracy and escalation procedures are implemented.
- Incident Review: Incident and near-miss reviews are performed.
- SIEM: Centralized log correlation in SIEM is planned as a future improvement.
- Domain Monitoring: Domain blacklisting monitoring currently reports 2/147.
- SSL Security: RELIANOID currently maintains an SSL Labs Security Report rating of A+.
Proactive Security & Threat Intelligence
RELIANOID continues to actively monitor and respond to malicious infrastructure and abuse indicators.
- AbuseIPDB: More than 32,000 malicious IP addresses have been reported through AbuseIP.
- Network Abuse Protection: Network abuse IP protection is implemented.
- Domain Blacklisting: Continuous monitoring is in place.
Lifecycle & Decommissioning
- Versioned releases with detailed release notes and migration guidance
- Patch advisories for security updates
- Automated secure key management and decommissioning
The latest security report confirms that software updates are issued on every release and communicated through the RELIANOID timeline.
Data Protection, Backup & Resilience
RELIANOID maintains data protection and resilience measures supporting application security and service continuity.
- Encryption: The latest report confirms encryption in transit as the current implemented control.
- Backup & Restoration: Backup and restoration processes are tested quarterly.
- Data Classification: Data classification and retention policies are maintained according to the Data Processing Agreement.
- DLP: DLP tool configuration and effectiveness are planned as a future improvement.
Incident Response & Security Awareness
RELIANOID maintains incident response and security awareness processes as part of its application security governance.
- Incident Response Team: The incident response team contact list is reviewed and maintained.
- Alert Escalation: Alert accuracy and escalation procedures are implemented.
- Incident Reviews: Incidents and near misses are reviewed.
- Incident Response Plan Testing: Formal review and testing of the Incident Response Plan is planned as a future improvement.
- Lessons Learned: Formal documentation and implementation of lessons learned is planned as a future improvement.
- Security Awareness: Security awareness training is delivered and completion is tracked.
- Phishing Simulations: Analysis of phishing simulations is planned as a future improvement.
- Threat Intelligence: Incorporation of new threat intelligence into security awareness content is planned.
Customer Guidance for Regulated Environments
We support customers with:
- Deployment and security hardening guides for on-prem and cloud platforms
- Support for security questionnaires and attestations managed by our compliance team
- SLA-backed enterprise support with engineer escalation for urgent cases
Third-Party Risk & Application Supply Chain
RELIANOID includes third-party security and supply chain considerations within its application security governance.
- Third-Party Libraries: Vulnerability monitoring is implemented for both services and product components.
- Product Libraries: Weekly vulnerability scans are performed against third-party libraries.
- Supplier Risk: Critical ICT suppliers are assessed for certifications, risks, SLA and resilience commitments, and contingency plans.
Commitment to Continuous Improvement
RELIANOID continuously enhances application security through:
- Quarterly security training for developers and staff
- Planned annual roadmap for platform and infrastructure security enhancements
- Continuous quarterly security reports with improvements and new controls
- Progressive alignment with ISO/IEC 27001, 27017, 27018, and sector-specific frameworks
Based on the latest 2026Q2 security assessment, the current improvement roadmap additionally includes:
- Automated SAST/DAST scanning for services.
- Additional deep vulnerability scanning.
- Centralized log correlation through SIEM.
- DLP tooling and effectiveness improvements.
- Formal review and testing of the Incident Response Plan.
- Tabletop or blue team security exercises.
- Formal documentation and implementation of lessons learned.
- Phishing simulation analysis.
- Incorporation of new threat intelligence into security awareness content.
- Continued remediation of vulnerabilities identified through security testing.
Document Reviews
| Date | Comment |
| 31st July 2025 | Document creation |
| 3rd September 2025 | Added company context, ASMP details, SSDLC practices, expanded security features, verification/testing, operational security, customer guidance, and continuous improvement |
| 30th June 2026 | Updated with the latest RELIANOID Security Compliance Report 2026Q2, including application security controls, vulnerability management, security testing, MFA, network protection, WAF, uptime, backup and restoration, incident response, security awareness, third-party risk, and continuous improvement measures |
Contact and Assurance
We welcome requests for detailed security documentation, risk mapping matrices, or compliance disclosures.
Contact our Compliance & Security Team
Download Latest Security Report