The controls auditors ask about, mapped and documented — not improvised during the audit.
| Framework | Status | What it covers |
|---|---|---|
| SOC 2 Type II | Annual, current report available under NDA | Security, availability, confidentiality |
| ISO 27001 | Certified | ISMS covering the coordination platform |
| GDPR | DPA available | Minimal metadata processing; regional coordination available |
| FedRAMP | In progress (roadmap) | Government workloads — contact us for the timeline |
| HIPAA | BAA available | For covered entities using Enterprise agreements |
Identity-based ACLs, least privilege by default, SCIM deprovisioning — evidence from the console.
Zero Trust →Network audit log, session recording, SIEM streaming for retention windows.
For security teams →Policy-as-code via Terraform — every change reviewed and versioned in your VCS.
Config as code →SOC 2 report, ISO certificate, DPA, and subprocessor list — one request, same-day reply.