Compliance

    Last reviewed:

    This is where we are on each compliance framework, in plain English. We label items honestly: Audit in progress means an auditor is engaged but the report isn't in our hands yet, and we won't claim it until it is.

    At a glance

    FrameworkStatusWhat it means
    SOC 2 Type IIAudit in progressAudit in progress with a top-tier auditor.
    GDPRAlignedAligned. Data Processing Agreement available.
    CCPAAlignedAligned. Honors do-not-sell and data-subject requests.
    HIPAAEnterpriseBusiness Associate Agreement available with our Enterprise plan.
    ISO 27001RoadmapPlanned for after SOC 2 Type II lands.
    DPAAlignedStandard Data Processing Agreement available on request.

    SOC 2 Type II

    We are working with a top-tier auditor toward SOC 2 Type II - the gold standard for SaaS security. The audit window opens this summer; the report follows. We will publish the report in our trust portal the moment we have it. Until then we will not display the AICPA SOC seal - its trademark rules forbid "in progress" use, and so do ours.

    GDPR

    We are aligned with the GDPR. We can sign a Data Processing Agreement at the start of any contract. Email privacy@pocodot.ai or download the template from our trust portal. We honour data-subject access, portability, and deletion requests in line with Article 15-17.

    CCPA

    We honour California Consumer Privacy Act do-not-sell and data-subject requests. We do not sell personal information; this is written into our privacy policy and our customer contracts.

    HIPAA

    Pocodot supports a HIPAA Business Associate Agreement on our Enterprise plan. Healthcare prospects: email security@pocodot.ai so we can sequence the BAA timeline with your procurement.

    ISO 27001

    On our roadmap after SOC 2 Type II lands. We do not claim ISO 27001 alignment until the controls are independently audited.

    Sub-processors and the 30-day notice

    We give 30 days' notice before adding any new sub-processor. The contractual notice is delivered as an in-product banner to all workspace admins on next sign-in, plus a direct email to the workspace billing contact. Anyone can also subscribe to the public RSS feed at /security/subprocessors.rss.

    Security questionnaires

    We turn around most security questionnaires in one business day. We can answer CAIQ, SIG-Lite, and your own templates. Pre-filled CAIQ and SIG-Lite are available in our trust portal. To request access, email security@pocodot.ai with your company name and a one-line description of the engagement.

    Where the evidence lives

    Ready to hire your first AI agent?

    Join thousands of teams using AI agents to automate work.

    Get Started Free