Cloud 101CircleEventsBlog

STAR Registry Listing for

Noname Security

Founded in 2013 by the Cloud Security Alliance, the Security Trust Assurance and Risk (STAR) registry encompasses key principles of transparency, rigorous auditing, and cloud security and privacy best practices.

Noname Security Logo

Noname Security

Noname Security protects APIs in real-time and detects vulnerabilities and misconfigurations before they are exploited. The Noname API Security Platform is an out-of-band solution that doesn’t require agents or network modifications, and offers deeper visibility and security than API gateways, load balancers, and WAFs, prioritizing risk based on the severity of the underlying security issue, combined with environmental context, including its accessibility and potential damage to the business.

Noname Security is the only solution that covers the entire API security scope across three pillars — API Posture Management, API Runtime Security, and Secure API SDLC and allows security teams to discover:

  • APIs, data, and metadata;
  • Find and inventory various kinds of API, including hypertext transfer protocol (HTTP), representational state transfer (RESTful), graph query language (GraphQL), simple object access protocol (SOAP), extensible markup language remote procedure call (XML-RPC), and Google remote procedure call (gRPC);
  • Discover legacy and rogue APIs not managed by an API gateway;
  • Catalogue API data and metadata;
  • Analyze API behavior;
  • Detect API threats;
  • Prevent attacks.
Organizations who have the CSA Trusted Cloud Provider seal demonstrate a commitment to organizational security. They are a CSA Corporate Member volunteer regularly for CSA, and have at least one staff member who has earned their CCSK.
Information about Noname Security
Listed Since: 01/04/2022
Last Updated: 09/15/2023

STAR Level 1

Self-Assessment & Partner-Provided

Consensus Assessments Initiative Questionnaire v4.0.2

CAIQ 4.0.2 Self-assessment
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No questions a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the CSA Cloud Controls Matrix (CCM).
(Deprecated)
Deprecated assessments do not necessarily indicate non-compliance. In this case, the self-assessment has not been updated in more than one year. We suggest contacting this organization directly to request that they submit an updated self-assessment.

STAR Level 2

Third-Party Audit

Organizations looking for a third-party audit can choose from one or more of the security and privacy audits and certifications.

Consensus Assessments Initiative Questionnaire v3.0.1

STAR Attestation
Provides guidelines for CPAs to conduct SOC 2 engagements using criteria from the AICPA (Trust Service Principles, AT 101) and the CSA Cloud Controls Matrix.