Our own posture
A compliance company without its own compliance is a punchline.
Here's exactly where we are. Updated as our own status changes — the same way your Trust Center will work.
- GDPRIn scope — DPA available
EU data residency; DPA available on request. GDPR is a regulation, not a certification.
- SOC 2Planned
No attestation today. We publish the auditor and timeline here once engaged.
- ISO 27001Planned
Targeted after SOC 2. No certificate today.
- Data residencyEU — Supabase (Frankfurt)
Primary data storage stays in the EEA.
- Encryption in transitHTTPS enforced
- Encryption at restManaged by Supabase
- MFA enforcementPlanned
Target: enforced for all staff accounts.
- Penetration testingPlanned
- Backup + disaster recoveryPlanned
RPO/RTO targets published once tested.
- Continuous monitoringPlanned
Want the long version? Email security@veylanai.com for our security questionnaire response. We will publish an attestation report here if and when one is issued.