Our own posture

A compliance company without its own compliance is a punchline.

Here's exactly where we are. Updated as our own status changes — the same way your Trust Center will work.

  • GDPR
    In scope — DPA available

    EU data residency; DPA available on request. GDPR is a regulation, not a certification.

  • SOC 2
    Planned

    No attestation today. We publish the auditor and timeline here once engaged.

  • ISO 27001
    Planned

    Targeted after SOC 2. No certificate today.

  • Data residency
    EU — Supabase (Frankfurt)

    Primary data storage stays in the EEA.

  • Encryption in transit
    HTTPS enforced
  • Encryption at rest
    Managed by Supabase
  • MFA enforcement
    Planned

    Target: enforced for all staff accounts.

  • Penetration testing
    Planned
  • Backup + disaster recovery
    Planned

    RPO/RTO targets published once tested.

  • Continuous monitoring
    Planned

Want the long version? Email security@veylanai.com for our security questionnaire response. We will publish an attestation report here if and when one is issued.

Security — Our own posture · Veylan