Compliance & Governance

We maintain comprehensive compliance frameworks and certifications to meet the regulatory requirements of enterprises across industries and geographies.

Compliance Frameworks

We align with industry-standard frameworks to ensure comprehensive compliance coverage.

SOC 2 Type II
In Progress
Security, availability, and confidentiality controls audited by independent third parties.
  • Expected completion: Q2 2025
  • Covers all Trust Service Criteria
  • Annual re-certification planned
GDPR Compliance
Compliant
Full compliance with EU General Data Protection Regulation for European customers.
  • Data Processing Agreements available
  • Right to be forgotten implemented
  • Data portability supported
CCPA/CPRA
Compliant
California Consumer Privacy Act and California Privacy Rights Act compliance.
  • Consumer rights portal
  • Opt-out mechanisms
  • Data deletion processes
ISO 27001
Planned 2025
Information Security Management System certification planned for comprehensive security.
  • Gap analysis completed
  • Implementation roadmap defined
  • Certification target: Q4 2025

Regional Compliance

We maintain compliance with regional data protection and privacy regulations worldwide.

United States

Active
  • SOC 2
  • CCPA/CPRA
  • HIPAA (Healthcare)
  • FedRAMP (Future)

European Union

Active
  • GDPR
  • Data Protection Act
  • NIS2 Directive

United Kingdom

Active
  • UK GDPR
  • Data Protection Act 2018

Canada

Planned
  • PIPEDA
  • Provincial Privacy Laws

Compliance Documentation

Access comprehensive documentation to support your procurement and compliance requirements.

Data Processing Agreement (DPA)

Standard contractual clauses for GDPR compliance and data processing.

Legal
Available on requestRequest

Subprocessor List

Complete list of third-party subprocessors and their security measures.

Transparency
PublicRequest

Security Whitepaper

Detailed technical documentation of our security architecture.

Technical
Available on requestRequest

Compliance Questionnaire

Pre-filled security and compliance questionnaire for procurement teams.

Procurement
Available on requestRequest

Subprocessors

Transparent list of third-party service providers who may process customer data.

Current Subprocessors
All subprocessors are bound by data processing agreements and maintain appropriate certifications.

Amazon Web Services (AWS)

Cloud InfrastructureUnited States

SOC 2ISO 27001FedRAMP

Auth0

Authentication ServicesUnited States

SOC 2ISO 27001

Stripe

Payment ProcessingUnited States

PCI DSSSOC 2

Intercom

Customer SupportIreland

SOC 2GDPR

Audit Readiness

Our comprehensive audit readiness program ensures we can quickly respond to customer audit requirements.

Documentation
  • Comprehensive policy library
  • Procedure documentation
  • Evidence collection processes
  • Change management records
Technical Controls
  • Automated compliance monitoring
  • Configuration management
  • Vulnerability management
  • Incident response procedures
Governance
  • Risk assessment framework
  • Vendor management program
  • Employee training records
  • Regular compliance reviews

Need Compliance Documentation?

Our compliance team is ready to provide the documentation and assurance your organization needs to move forward with confidence.