This is where we are on each compliance framework, in plain English. We label items honestly: Audit in progress means an auditor is engaged but the report isn't in our hands yet, and we won't claim it until it is.
At a glance
| Framework | Status | What it means |
|---|---|---|
| SOC 2 Type II | Audit in progress | Audit in progress with a top-tier auditor. |
| GDPR | Aligned | Aligned. Data Processing Agreement available. |
| CCPA | Aligned | Aligned. Honors do-not-sell and data-subject requests. |
| HIPAA | Enterprise | Business Associate Agreement available with our Enterprise plan. |
| ISO 27001 | Roadmap | Planned for after SOC 2 Type II lands. |
| DPA | Aligned | Standard Data Processing Agreement available on request. |
SOC 2 Type II
We are working with a top-tier auditor toward SOC 2 Type II - the gold standard for SaaS security. The audit window opens this summer; the report follows. We will publish the report in our trust portal the moment we have it. Until then we will not display the AICPA SOC seal - its trademark rules forbid "in progress" use, and so do ours.
GDPR
We are aligned with the GDPR. We can sign a Data Processing Agreement at the start of any contract. Email privacy@pocodot.ai or download the template from our trust portal. We honour data-subject access, portability, and deletion requests in line with Article 15-17.
CCPA
We honour California Consumer Privacy Act do-not-sell and data-subject requests. We do not sell personal information; this is written into our privacy policy and our customer contracts.
HIPAA
Pocodot supports a HIPAA Business Associate Agreement on our Enterprise plan. Healthcare prospects: email security@pocodot.ai so we can sequence the BAA timeline with your procurement.
ISO 27001
On our roadmap after SOC 2 Type II lands. We do not claim ISO 27001 alignment until the controls are independently audited.
Sub-processors and the 30-day notice
We give 30 days' notice before adding any new sub-processor. The contractual notice is delivered as an in-product banner to all workspace admins on next sign-in, plus a direct email to the workspace billing contact. Anyone can also subscribe to the public RSS feed at /security/subprocessors.rss.
Security questionnaires
We turn around most security questionnaires in one business day. We can answer CAIQ, SIG-Lite, and your own templates. Pre-filled CAIQ and SIG-Lite are available in our trust portal. To request access, email security@pocodot.ai with your company name and a one-line description of the engagement.
Where the evidence lives
- Security & Privacy - the customer-voice landing page
- Security architecture - the long technical version for security teams
- Governance - admin controls, audit log, retention
- Responsible AI - no-train commitments and model selection rationale
- Sub-processors - the companies that help us run Pocodot