PCI DSS Compliance Whitepaper
Comprehensive mapping of all 12 PCI DSS 4.0 control requirements to TR7 ASP modules (ADC, WAAP, GTM, AAM). Includes architectural patterns and implementation guidance.
TR7 maintains the highest security standards validated through independent audits and internationally recognized certifications, ensuring enterprise-grade protection and regulatory compliance for your organization.
Highest Commercially Practical Security Level
Our security products have been evaluated to EAL4+ (Evaluation Assurance Level 4 Augmented), the highest level of assurance that is practically achievable for commercial products. This certification is recognized by 31 governments worldwide through the Common Criteria Recognition Arrangement (CCRA).
Search "TR7" on Common Criteria Portal to find our certification
TR7's information security management system is certified to ISO 27001:2022, the international standard for managing information security. This certification demonstrates our systematic approach to managing sensitive company and customer information.
Our quality management system is certified to ISO 9001:2015, demonstrating our commitment to consistent product quality, customer satisfaction, and continuous improvement in all our processes and services.
TR7 has successfully completed an independent PCI DSS v4.0.1 assessment conducted by a Qualified Security Assessor (QSA). Completed in July 2026, the assessment is documented in the Attestation of Compliance (AoC) with an overall result of Compliant — meaning that all applicable requirements within the assessed scope were met. The assessment confirms that the security controls, processes, and infrastructure within scope that could affect the security of cardholder data meet the applicable PCI DSS requirements. The assessed scope includes TR7's Web Application Firewall, Load Balancer, Access Gateway Service, and Global Traffic Manager solutions. In addition, our Web App & API Protection (WAAP) and Application Delivery Controller (ADC) solutions support customers' own PCI DSS compliance efforts in areas such as web application security, encryption, and network segmentation. The Attestation of Compliance (AOC) is available to customers upon request.
Our systems and controls have undergone SOC 2 Type II examination, providing independent validation of our security, availability, processing integrity, confidentiality, and privacy controls over an extended period.
TR7 solutions are designed to help organizations meet the stringent privacy and data protection requirements of the European Union's General Data Protection Regulation, including data minimization, encryption, and privacy by design principles.
TR7 helps organizations achieve and maintain compliance across multiple regulatory frameworks
In-depth whitepapers and reference documents that map TR7 modules to specific compliance requirements.
Comprehensive mapping of all 12 PCI DSS 4.0 control requirements to TR7 ASP modules (ADC, WAAP, GTM, AAM). Includes architectural patterns and implementation guidance.
Learn how TR7's certified security solutions can help your organization meet compliance requirements while providing superior protection.