Skip to main content
SVDY Logo

Compliance program

Where the regulatory landscape touches a workforce-management SaaS, and what we're doing about it. Honest state of the program — what's shipped, what's in progress, what's deliberately not yet on the roadmap.

Last updated:May 24, 2026

Compliance framework

svdy operates a continuous compliance program rather than a point-in-time checklist. Concretely:

• Privacy-by-design — every new feature passes a privacy impact assessment before merge if it touches PII. The Wave 1-4 privacy audit log lives in our internal tracker; visible outcomes are the GDPR Art. 9 face-recognition consent flow, the right-to-erasure mechanism, and the 30-day customer-data deletion window after subscription cancellation.

• Documented controls — security policies (access control, change management, vendor management, incident response) are version-controlled and reviewed annually.

• Vendor management — every sub-processor undergoes a documented intake review before getting access to customer data. The 5 current sub-processors are listed at /trust/sub-processors; updates trigger a 30-day customer notification.

• Continuous monitoring — pre-SOC 2, this is internal (audit logs, access reviews, change tickets). Once Vanta is wired up (Q3-Q4 2026), evidence collection becomes continuous and externally auditable.

• Regulatory radar — we track legislation that affects our customer base (US state privacy laws, EU NIS2, China PIPL, Brazil LGPD) and adjust our DPA + product features as scope expands.

Standards we follow

We align with these industry-standard frameworks. Following ≠ certified — see /trust/soc2 for what's formally audited and when.

• NIST Cybersecurity Framework (CSF) 2.0: Internal controls mapped to Identify / Protect / Detect / Respond / Recover. Self-assessed; basis for SOC 2 Type II audit (Q1 2027 onwards).

• OWASP Top 10 (web application): Engineering practice covers the OWASP Top 10 (2021): injection prevention via parameterized queries, broken access control via tenant-scoped queries, etc. SAST tools run pre-merge; SCA via Dependabot.

• CIS AWS Foundations Benchmark: AWS configuration aligned with CIS Foundations v2.0 controls — IAM least privilege, MFA on root, encrypted EBS, S3 block public access, audit logs to centralized account. Self-attested today; SOC 2 audit will validate Q2 2027.

• ISO/IEC 27001 — directional, not certified: Our control set borrows from ISO 27001 Annex A controls. Formal certification is a Phase 2 (post-SOC 2 Type II, likely 2027-2028) — only initiated if EU enterprise customers ask for it.

Regional regulations

Where svdy customer data touches regulated jurisdictions, and our posture in each:

• European Union & UK: GDPR (EU 2016/679), UK GDPR + Data Protection Act 2018, ePrivacy Directive (cookies)

EU + UK customers covered by our Standard Contractual Clauses (2021 version) plus the UK Addendum, included in the DPA at /trust/dpa. Privacy Policy is GDPR Art. 13/14-aligned. Data subject rights mechanism via legal@svdy.com, 30-day response. Data residency: us-east-1 today; EU / APAC region availability is on the Enterprise tier roadmap (2027).

• United States: CCPA / CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah)

We respect Do-Not-Sell, Right-to-Know, and Right-to-Delete under all applicable US state privacy laws. Privacy Policy includes the CCPA-mandated category disclosures and retention windows. We do NOT sell personal information as defined under §1798.140(t).

• Brazil & APAC: LGPD (Brazil), Singapore PDPA, Australia Privacy Act

Adherence in scope where customer base exists. China PIPL data-localization requirements are not currently met (no mainland-China data residency); customers with mainland-China workforce must keep that data offshore in our existing us-east-1 region until LATAM / APAC region build-out (post-2027).

Audits and attestations

What's actually audited today, what's coming, what we deliberately aren't pursuing:

• SOC 2 Type II — IN PROGRESS: Targeted Q1 2027 audit kickoff (6-month observation), Q3 2027 report issued. Vanta + A-LIGN selected. Public timeline at /trust/soc2.

• GDPR — self-assessed: GDPR has no formal compliance certification (regulators do not issue certificates). We maintain a GDPR-ready architecture verified through our internal privacy audit Wave 1-4. Our DPA is available on request at /trust/dpa for customers who need a written processor agreement.

• ISO 27001 — Phase 2: Not yet engaged. Expected post-SOC 2 (2027-2028) if EU enterprise demand justifies the audit cost. Update at /trust/soc2 when started.

• HIPAA / PCI-DSS / FedRAMP — out of scope: svdy is not currently a HIPAA business associate, is not in PCI-DSS scope (Stripe handles cardholder data on their certified platform), and is not pursuing FedRAMP. Federal / regulated-industry customers should reach out to support@svdy.com to discuss whether we can fit your specific compliance need before signing up.

Need our compliance documentation, regional regulatory attestations, or SOC 2 timeline? Email legal@svdy.com — see the SOC 2 progress at /trust/soc2.