Skip to main content
Building multi-tenant SaaS on the Base Platform — .NET, React, and cloud-native architecture.Explore Base Platform

Trust Center

Compliance programs

Published programs and roadmap items for enterprise buyers. Unverified items are labeled Roadmap — never as certifications.

Compliance

Programs and roadmap

Published compliance items. Unverified programs are labeled Roadmap — never as certifications.

GDPR

Roadmap

Privacy-by-design delivery patterns for minimization, access control, retention, and subject-rights workflows.

Roadmap: Formalize DPIA templates and processor evidence packs for customer reviews.

CCPA

Roadmap

Consumer privacy request handling patterns for U.S. state privacy obligations where applicable.

Roadmap: Publish request workflows and retention matrices when U.S. processing scope is confirmed.

ISO 27001

Roadmap

Information security management system formalization path.

Roadmap: Define ISMS scope, control owners, and evidence collection before any certification claim.

SOC 2

Roadmap

Trust Services Criteria control evidence for operated services — not attested today.

Roadmap: Build control inventory and independent attestation plan when operated SaaS scope requires it.

HIPAA

Roadmap

Healthcare privacy and security patterns for appropriately scoped engagements.

Roadmap: BAAs, PHI minimization, and environment isolation defined per engagement — no general HIPAA certification claim.

PCI DSS

Roadmap

Payment architectures that prefer tokenized providers and minimize card-data exposure.

Roadmap: Scope reduction guidance only until a specific PCI assessment is commissioned.

Cyber Essentials

Roadmap

Baseline cyber hygiene controls for organizations that require Cyber Essentials alignment.

Roadmap: Assess applicability and evidence needs before any badge or claim is published.

AI Governance

Roadmap

Human oversight, privacy-first model use, evaluation, and risk review for AI features we deliver.

Roadmap: Expand evaluation checklists and customer-facing AI policy detail as products reach Live status.

OWASP practices

Roadmap

Secure SDLC habits informed by OWASP guidance — not a certification.

Roadmap: Continue mapping reviews to ASVS-informed controls by application risk.

Accessibility (WCAG)

Roadmap

WCAG-oriented design and engineering targets for interfaces we control — not an audited conformance claim.

Roadmap: Publish accessibility statement updates when formal audits are completed.

FAQ

Compliance FAQ

Certification status, HIPAA support, and how we handle customer audits.

Need compliance evidence?

Request documentation packages and questionnaire support through our vendor security workflow.