Compliance

Honest about where we stand.

We distinguish between what is operational, what is in progress, and what is planned. No overclaiming — just transparent status.

European Union

EU regulatory compliance.

General Data Protection Regulation

Operational

Comprehensive EU data protection for all personal data processing.

EU
  • Art. 15 — Right to Access: Self-service DSAR with data export
  • Art. 16 — Right to Rectification: Users can update own information
  • Art. 17 — Right to Erasure: Full deletion cascade across 66 tables, file storage, and vector embeddings
  • Art. 20 — Data Portability: Standard format exports via DSAR workflow
  • Art. 28 — Processor Obligations: Runtime paid-tier enforcement prevents free-tier AI usage
  • Art. 6(1)(f) — Lawful Basis: Legitimate Interest with three-part EDPB balancing test
  • Data residency enforced in EU (Germany, Finland, Netherlands)

EU AI Act

Operational

Regulation 2024/1689 compliance for high-risk AI systems.

EU
  • Art. 9 — Risk Management: Quarterly governance reports with risk indicators
  • Art. 10 — Data Governance: PII redaction and audit logging on all AI data flows
  • Art. 12 — Record-Keeping: AI acceptance metrics, audit logs, governance reports
  • Art. 14 — Human Oversight: Manager training gate (require_ai_certified)
  • Art. 50 — Transparency: AI content labelling throughout the platform
  • Annex III Category 4b classification (employment and worker management)
  • Rubber-stamping detection with 4 monitored indicators
International

International standards.

ISO 27001

In Progress

Information security management system certification.

Global
  • Gap assessment underway (Q3 2026)
  • Information security management system documentation in progress
  • Formal certification audit targeted for H1 2027
  • Recognised standard for EU and international enterprise requirements
North America

North American compliance.

SOC 2

Planned

Service Organization Control 2 for North American enterprise requirements.

NA
  • Readiness assessment complete (Security + Availability + Confidentiality + Privacy criteria)
  • Compliance platform evaluation (Vanta, Drata) underway
  • Type I audit planned following ISO 27001 certification
  • Many controls already operational from ISO 27001 preparation

HIPAA

Operational

Health Insurance Portability and Accountability Act compliance for healthcare verticals.

NA
  • Business Associate Agreement (BAA) with cloud AI providers
  • Encrypted PHI at rest and in transit
  • Audit logging of all PHI access with 7-year retention
  • Zero data retention for AI processing
  • Access controls and authentication for healthcare data
  • Applicable to DermGeist healthcare vertical

CCPA

Operational

California Consumer Privacy Act — consumer data rights for California residents.

NA
  • Right to know what data is collected
  • Right to delete personal information
  • Right to opt out of data sales (we never sell data)
  • Right to non-discrimination
  • Self-service data export and deletion tools
Roadmap

Certification timeline.

Our security and compliance roadmap through H1 2027.

Q2 2026

Dependency scanning in CI

Operational

pip-audit, OSV-Scanner, lockfile integrity, and supply chain checks on every push

DPIA completion

In Progress

Data Protection Impact Assessment with enterprise customers

Q3 2026

Security training programme

Planned

Initial rollout for all staff; annual GDPR refresher

ISO 27001 gap assessment

In Progress

Information security management system documentation

Q4 2026

Penetration test

Planned

Gray-box (authenticated + unauthenticated), full application and API scope. EU-based firm

WCAG 2.1 AA audit

Planned

Third-party accessibility audit

DR drill

Planned

Full restore test; validate RTO (<4h) and RPO (<24h) targets

H1 2027

ISO 27001 certification

Planned

Formal certification audit (dependent on gap assessment)

Application-level encryption

Planned

Per-tenant AES-256-GCM field-level encryption deployment

Need detailed compliance evidence?

Request our Security & Compliance Evidence Pack with full control matrices and technical architecture details.

Request Evidence Pack