Compliance program
Where the regulatory landscape touches a workforce-management SaaS, and what we're doing about it. Honest state of the program — what's shipped, what's in progress, what's deliberately not yet on the roadmap.
Compliance framework
SVDY operates a continuous compliance program rather than a point-in-time checklist. Concretely:
• Privacy-by-design — every new feature passes a privacy impact assessment before merge if it touches PII. The Wave 1-4 privacy audit log lives in our internal tracker; visible outcomes are the GDPR Art. 9 face-recognition consent flow, the right-to-erasure mechanism, and the 90-day customer-data deletion window after subscription cancellation.
• Documented controls — security policies (access control, change management, vendor management, incident response) are version-controlled and reviewed annually.
• Vendor management — every sub-processor undergoes a documented intake review before getting access to customer data. The 5 current sub-processors are listed at /trust/sub-processors; updates trigger a 30-day customer notification.
• Continuous monitoring — pre-SOC 2, this is internal (audit logs, access reviews, change tickets). Once Vanta is wired up (Q3-Q4 2026), evidence collection becomes continuous and externally auditable.
• Regulatory radar — we track legislation that affects our customer base (US state privacy laws, EU NIS2, China PIPL, Brazil LGPD) and adjust our DPA + product features as scope expands.
Standards we follow
We align with these industry-standard frameworks. Following a framework is not the same as being certified — see /trust/soc2 for what's formally audited and when.
• NIST Cybersecurity Framework (CSF) 2.0: Internal controls mapped to Identify / Protect / Detect / Respond / Recover. Assessed by our own team today, not by an outside auditor; this is the basis for the SOC 2 Type II audit (Q1 2027 onwards).
• OWASP Top 10 (web application): Our engineering practice covers the OWASP Top 10 (2021), the industry list of the most common web application risks. For example, database queries are parameterized so submitted text cannot change the query, and every query is limited to the requesting organization's own data, so one customer can never reach another customer's records. Automated code scanning (SAST) and dependency scanning (SCA, via Dependabot) run on every change before it is merged.
• CIS AWS Foundations Benchmark: AWS configuration aligned with CIS Foundations v2.0 controls — IAM least privilege, MFA on root, encrypted EBS, S3 block public access, audit logs to centralized account. Today this is our own internal assessment, not yet checked by an outside auditor; the SOC 2 audit will validate it in Q2 2027.
• ISO/IEC 27001 — directional, not certified: Our control set borrows from ISO 27001 Annex A controls. Formal certification is a Phase 2 (post-SOC 2 Type II, likely 2027-2028) — only initiated if EU enterprise customers ask for it.
Regional regulations
Where SVDY customer data touches regulated jurisdictions, and our posture in each:
• European Union & UK: GDPR (EU 2016/679), UK GDPR and the Data Protection Act 2018, ePrivacy Directive (cookies)
EU + UK customers covered by our Standard Contractual Clauses (2021 version) plus the UK Addendum, included in the DPA at /trust/dpa. Privacy Policy is GDPR Art. 13/14-aligned. Data subject rights mechanism via legal@svdy.com, 30-day response. Data residency: us-east-1 today; EU / APAC region availability is on the Enterprise tier roadmap (2027).
• United States: CCPA / CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah)
We respect Do-Not-Sell, Right-to-Know, and Right-to-Delete under all applicable US state privacy laws. Privacy Policy includes the CCPA-mandated category disclosures and retention windows. We do NOT sell personal information as defined under §1798.140(t).
• Brazil & APAC: LGPD (Brazil), Singapore PDPA, Australia Privacy Act
Adherence in scope where customer base exists. China PIPL data-localization requirements are not currently met (no mainland-China data residency); customers with mainland-China workforce must keep that data offshore in our existing us-east-1 region until LATAM / APAC region build-out (post-2027).
Audits and attestations
What's actually audited today, what's coming, what we deliberately aren't pursuing:
• SOC 2 Type II — IN PROGRESS: Targeted Q1 2027 audit kickoff (6-month observation), Q3 2027 report issued. Vanta + A-LIGN selected. Public timeline at /trust/soc2.
• GDPR — internal assessment: GDPR has no formal compliance certification (regulators do not issue certificates). We maintain a GDPR-ready architecture verified through our internal privacy audit Wave 1-4. Our DPA is available on request at /trust/dpa for customers who need a written processor agreement.
• ISO 27001 — Phase 2: Not yet engaged. Expected post-SOC 2 (2027-2028) if EU enterprise demand justifies the audit cost. Update at /trust/soc2 when started.
• HIPAA / PCI-DSS / FedRAMP — out of scope: SVDY is not currently a HIPAA business associate, is not in PCI-DSS scope (Stripe handles cardholder data on their certified platform), and is not pursuing FedRAMP. Federal / regulated-industry customers should reach out to support@svdy.com to discuss whether we can fit your specific compliance need before signing up.
Need our compliance documentation, regional regulatory attestations, or SOC 2 timeline? Email legal@svdy.com — see the SOC 2 progress at /trust/soc2.
