Trust Center / CSA STAR
CSA STAR
A cloud-specific security registration, inherited through Microsoft Azure the same way SOC 2 is.
What It Is
The Cloud Security Alliance’s Security, Trust, Assurance, and Risk (STAR) program assesses cloud providers against the Cloud Controls Matrix (CCM), a security framework built specifically for cloud services.
What It Majorly Requires, and How VIDIZMO Supports It
- A cloud-specific security assessment against the Cloud Controls Matrix. Inherited through Microsoft Azure’s own CSA STAR registration, since VIDIZMO’s infrastructure runs on Azure.
Scope & Limitations
VIDIZMO does not hold a CSA STAR registration independently. ISO 27001 is the certification VIDIZMO holds directly.
FAQ
CSA STAR, asked and answered
What is CSA STAR, and why does it matter for evaluating VIDIZMO's cloud security?
CSA STAR (Security, Trust, Assurance and Risk) is a cloud security assurance program from the Cloud Security Alliance that validates a cloud provider's security controls. It gives prospects an independent benchmark for assessing the security posture of VIDIZMO's cloud-hosted deployments.
Does VIDIZMO hold its own CSA STAR registration, or is it inherited?
VIDIZMO's CSA STAR alignment is inherited through Microsoft Azure's own CSA STAR registration, since VIDIZMO's cloud offering runs on Azure infrastructure. This mirrors how VIDIZMO aligns with SOC 2 as well.
How does inheriting a compliance registration from Azure actually work?
Because VIDIZMO's cloud environment is built on Microsoft Azure, the underlying infrastructure, data centers, and physical/network security controls are already covered by Azure's CSA STAR registration. VIDIZMO's application layer then operates within that assured cloud foundation rather than requiring a separate registration.
Does CSA STAR alignment apply to on-premises or air-gapped VIDIZMO deployments?
CSA STAR is a cloud-specific assurance program, so it applies to VIDIZMO's cloud-hosted deployments on Azure. On-premises or air-gapped deployments should be evaluated against VIDIZMO's other security documentation rather than CSA STAR.
How is this different from VIDIZMO commissioning its own independent CSA STAR audit?
Rather than running a separate CSA STAR assessment, VIDIZMO relies on Azure's existing registration to cover the cloud infrastructure layer, the same approach many SaaS vendors take instead of duplicating certifications their cloud provider already holds.
Need our security documentation?
Tell us what your review requires and we will send the relevant evidence.