Compliance
In this document
Introduction
SorviAI holds no third-party security certification today. No ISO 27001 certificate, no SOC 2 report, no attestation of any kind. We would rather you read that in the first line of this page than find it out three weeks into a procurement review.
What follows is the rest of the answer. Which standards exist and what each one actually certifies. Which one we are pursuing and by when. What we can put in a reviewer’s hands today in place of a certificate. And the regulations we comply with, which are a different thing from audits we have passed, and are often what the question was really about.
If your policy requires a certificate we do not hold, What we provide instead sets out what we can offer, and Requesting documents tells you how to ask for it. Many organisations have a documented route for pre-certification vendors. What no organisation has a route for is discovering that something on a vendor’s website was untrue.
About this page, and how it differs from Security
This is the distinction that almost everybody collapses, and the whole page depends on it, so it is worth stating flatly.
- Security is our own account of what we do. Self-reported. It lives on our Security page.
- Compliance is somebody else’s verification that we do it. Externally attested. That is this page.
“We encrypt customer data at rest” is a statement for the Security page. “An accredited auditor tested our encryption controls across a twelve-month window and issued an unqualified opinion” is a statement for this one. The first is a description. The second is evidence produced by someone with no commercial interest in the answer.
So this page answers one question, in as few words as it can: who checked, and can we see the report?
Certification status
SorviAI holds no third-party security certification or attestation.
Last confirmed [STATUS CONFIRMED DATE]. If this sentence ever changes, it changes here first and the certificate or report is available on request the same day.
The table below is the complete list of the standards a reviewer is likely to ask us about, grouped the way procurement teams usually group them. Every one carries the same status today. It is a long table for a short answer, and it is here because the more useful thing than a single “no” is knowing that we understand which of these apply to us, which do not, and why.
| Standard | What it would attest | Status | Note |
|---|---|---|---|
| Information security management | |||
| ISO/IEC 27001 | That we operate a documented information security management system, audited by an accredited body | Under evaluation | One of the two candidates in the roadmap |
| ISO/IEC 27017 | Cloud-specific security controls, as an extension to ISO 27001 | Not held | An extension, not a substitute. Cannot precede a live 27001 certificate |
| ISO/IEC 27018 | Protection of personal data in a public cloud, as an extension to ISO 27001 | Not held | As above |
| ISO/IEC 27701 | A privacy information management system, as an extension to ISO 27001 | Not held | As above. Relevant later, given the personal data our customers hold |
| ISO 22301 | A business continuity management system | Not held | Depends on disaster recovery work that is not yet complete. See Our security architecture |
| Service organisation attestations | |||
| SOC 2 Type II | That our controls operated effectively across a window of six to twelve months | Under evaluation | The other candidate in the roadmap, and the one most enterprise buyers mean by “SOC 2” |
| SOC 2 Type I | That our controls were designed appropriately at a single point in time | Not held | Sometimes taken as a first step towards Type II. We would state the type, never just “SOC 2” |
| SOC 1 (SSAE 18 / ISAE 3402) Type II | Controls relevant to a customer’s own financial reporting | Not held | Worth naming, because SorviAI holds general ledgers and a customer’s external auditor may eventually ask. Not in current scope |
| SOC 3 | A public summary of a SOC 2 examination | Not held | Only exists once a SOC 2 does |
| Self-assessment and baseline schemes | |||
| CSA STAR Level 1 | A published self-assessment against the Cloud Security Alliance questionnaire | Planned | A self-assessment, not an audit, and we will label it as one. See the roadmap |
| Cyber Essentials / Cyber Essentials Plus | A UK government-backed baseline of technical controls; “Plus” adds hands-on verification | Not held | Under consideration if UK public-sector demand appears |
| Sector and regional schemes | |||
| PCI DSS | That cardholder data is handled to the card schemes’ standard | Scope question | Card data does not enter SorviAI systems. Payments and PCI DSS states our position precisely |
| HIPAA | Nothing. No HIPAA certification exists, for anyone | Not applicable | SorviAI is not offered for protected health information and we sign no Business Associate Agreement |
| TX-RAMP, ENS, NCA, NHS DSPT | Public-sector cloud authorisation in Texas, Spain, Saudi Arabia and the UK NHS respectively | Not held | Outside the markets we currently sell into. Listed so the absence is deliberate rather than an oversight |
What “not held” does and does not mean
It does not mean the controls do not exist. Tenant isolation, tenant-scoped authentication, role-based access control and audit logging are all built and running, and Our security architecture links to where they are described in detail.
It means no independent party has tested them and issued a report. Those are two different claims and we are not going to blur them, because blurring them is precisely what a certification exists to prevent.
What we provide instead, today
A certificate is a way of answering a reviewer’s questions without their having to ask. Where we cannot hand over the certificate, we can still answer the questions. This is everything available right now.
| What | What it is | How to get it | Turnaround |
|---|---|---|---|
| Completed security questionnaire | We complete yours. We do not require you to use a form of ours instead, and we do not charge for it | Email it to us, contact details | [N] business days |
| Security documentation | How tenant isolation, authentication, authorisation and audit logging actually work, with the gaps stated | Public, no request needed | Read now |
| Data Processing Addendum | Article 28 terms, pre-signed by us, ready for you to counter-sign | Public | Read now |
| Sub-processor list | Every third party with access to customer personal data, with purpose, location and safeguard | Public, with change notice you can subscribe to | Sub-processors |
| Architecture review call | A call with an engineer who has read the code, not an account manager reading a script | Ask us, contact details | Usually within a week |
| Contractual commitments | Where a control matters enough to your risk team, we will commit to it in the agreement rather than only describing it | Through your commercial contact | Case by case |
| Penetration test summary | An external test report summary | Not yet available | Roadmap |
| Insurance certificate | Cyber and professional indemnity cover | [CONFIRM COVER AND LIMITS] | On request |
| Customer references | Existing customers in a comparable position, where they agree to it | Ask us, contact details | Subject to their consent |
Certification roadmap
Two frameworks are worth pursuing and one of them is worth pursuing first. Which one is a commercial question rather than a technical one, and the honest deciding factor is where the revenue is, not which sounds more impressive.
- Selling primarily to United States buyers, the answer is SOC 2 Type II.
- Selling primarily to European, UK, Indian and government buyers, the answer is ISO 27001.
- Both are six to twelve month projects with real external cost and meaningful internal time. Neither is a document exercise that compresses into a sprint, and we are not going to pretend otherwise on a roadmap.
Our current position, and the date it was set: [CHOSEN FRAMEWORK], decided [DECISION DATE].
The stages, and where we are
| Stage | What happens | Target |
|---|---|---|
| Readiness assessment | A gap analysis against the chosen framework, carried out with an external adviser. Produces the list of what is missing | [DATE] |
| Remediation | Closing the gaps. For us these are mostly infrastructure rather than paperwork: encryption at rest evidenced at a stated layer, backups with tested restores, agreed recovery targets, a written incident response runbook, multi-factor authentication, and a first external penetration test | [DATE] |
| Observation windowSOC 2 Type II only | Controls have to run, and be evidenced running, for six to twelve months before the auditor can report on them. This is the part that cannot be shortened by spending more | [FROM] to [TO] |
| Stage 1 and Stage 2 auditISO 27001 only | A documentation review, then the certification audit itself, by an accredited body | [DATE] |
| Report or certificate issued | Published in Certification status the day it exists, with the report itself available under NDA | [DATE] |
The standards, explained
Written for the reviewer who has been handed a policy naming a framework and now has to work out what it would actually tell them about us. This section holds no claims about SorviAI at all; every status is in Certification status.
ISO/IEC 27001
Certifies that an organisation operates an information security management system: documented policies, a risk assessment method, a defined set of controls, internal audits and management review. It certifies that security is run as a system. It does not certify that any individual control is strong.
Issued by an accredited certification body after a two-stage audit, then maintained through annual surveillance audits with full recertification every three years. Preparation typically runs six to twelve months and is more a documentation and process undertaking than an engineering one.
Its extensions. ISO 27017 adds cloud-specific controls, ISO 27018 adds protection of personal data in a public cloud, and ISO 27701 adds a privacy management system. All three ride on a live 27001 certificate. A vendor citing 27018 without 27001 is describing something that cannot exist.
SOC 2
Not a certification but an attestation: a report produced by a CPA firm on controls measured against five trust services criteria. Security is mandatory; availability, processing integrity, confidentiality and privacy are optional scope. Two reports naming the same framework can therefore cover very different ground, which is why scope is worth asking about.
| Report | What it tests | Over what period |
|---|---|---|
| Type I | Whether controls were designed appropriately | A single point in time |
| Type II | Whether controls operated effectively | A window, typically 6 to 12 months |
Type II is substantially harder, substantially more expensive, and the one enterprise buyers mean when they say “SOC 2”. A vendor writing “SOC 2” without the type reads as evasion, and a reviewer will ask.
A SOC 2 report is not a public document. What a vendor publishes is that they hold one; the report itself is released under NDA. A bridge letter covers the gap between the end of the last window and today.
SOC 1, and why it appears here at all
SOC 1 reports on controls relevant to a customer’s own financial reporting, rather than on security generally. It is unusual on a SaaS compliance page and it is on ours because SorviAI holds general ledgers, journals and invoices. If a customer’s external auditor eventually places reliance on our system, SOC 1 is the report they will ask for. It is not in our current scope, and we would rather say that in advance than be surprised by the question.
CSA STAR
A registry run by the Cloud Security Alliance, at three levels: Level 1 is a published self-assessment, Level 2 is a third-party audit built on ISO 27001 or SOC 2, Level 3 is continuous monitoring. Level 1 entries are free and self-published, so appearing in the registry is not itself a certification, and any vendor presenting it as one is overstating it.
Cyber Essentials and Cyber Essentials Plus
A UK government-backed scheme covering a baseline of five technical control areas. The base level is a verified self-assessment; “Plus” adds hands-on technical testing by an assessor. Both are far cheaper and faster than ISO 27001, and some UK public-sector contracts require one, so it can be the right first step for reasons that have nothing to do with which framework is more rigorous.
PCI DSS
Applies only to organisations that store, process or transmit cardholder data. It is a scope question before it is a compliance question, and Payments and PCI DSS sets out our scope.
HIPAA
Worth stating plainly because the claim is so common: there is no such thing as HIPAA certification. No body issues one. What exists is a Business Associate Agreement between a covered entity and its vendor, and, optionally, an independent examination against the Security and Privacy Rules, usually delivered as a SOC 2 report with HIPAA criteria added. A vendor describing itself as “HIPAA certified” is describing something that does not exist, which is a useful thing to know about how they write the rest of their claims.
Regulations we comply with
These are laws we are subject to, not audits we have passed. No certificate exists for most of them, and no auditor issues one, so this section is a statement of practice that links to the documents carrying the substance.
| Regulation | Why it reaches us | Our position | Detail lives in |
|---|---|---|---|
| GDPREU / EEA | It applies by where your users are, not by where we are incorporated. One customer in the EEA brings us into scope | Processor for the data in your workspace, controller for your account and our own marketing data. Signable DPA, and Standard Contractual Clauses for transfers | GDPR page and DPA |
| UK GDPR and Data Protection Act 2018United Kingdom | UK customers and users | The same posture, with the UK transfer addendum in place of the EU clauses | GDPR page and DPA |
| Digital Personal Data Protection Act 2023India | We operate from India | Data fiduciary for our own account data, and processing customer data on our customers’ instructions. See the note below on commencement | Privacy Policy |
| CCPA and CPRA, and comparable US state lawsUnited States | California residents and residents of other states with comparable laws | Service provider. We do not sell or share personal information as those terms are defined, and we run no advertising | Privacy Policy |
| PECR and the ePrivacy DirectiveUK / EEA | Storing anything in a visitor’s browser | Nothing beyond strictly necessary storage and preferences you set yourself, which is why there is no consent banner | Cookie Policy |
Why none of these rows say “compliant”
“GDPR compliant” as a standalone claim carries almost no information. Nobody certifies it, and a reviewer asking about GDPR is not looking for the adjective. They need two concrete things: a data processing agreement they can sign, and a lawful mechanism for the transfer.
So each row above points at the document rather than asserting a state. If you find yourself unable to get from a row to the thing it names, that is a fault worth reporting to us, and our contact details are below.
Payments and PCI DSS
Card data does not enter SorviAI systems. That single fact settles most of what a reviewer needs to know here, but it is worth setting out how, because the difference between “we are compliant” and “we are out of scope” matters and is frequently blurred.
Payments are handled by [PAYMENT PROVIDERS], who are assessed as PCI DSS compliant service providers. Card details are entered into fields hosted by the provider and exchanged for a token. What SorviAI stores is that token and [CONFIRM: LAST FOUR DIGITS, CARD BRAND, EXPIRY]. The primary account number never reaches our servers, our logs or our backups.
The practical consequence is that our own PCI scope is minimal, in the territory a self-assessment questionnaire covers rather than a full assessment. We state that as a scope position and nothing more.
Storefronts run by our customers
Businesses using SorviAI to sell through a storefront take payment through the same provider integration, on the same basis. A customer who connects their own payment processor instead takes on whatever scope that processor’s arrangement carries. That scope is theirs, not ours, and it is worth their asking the question before they connect it.
Infrastructure and sub-processors
Every third party with access to customer personal data is listed publicly, with what they do, where they are and what safeguard is in place. The list is versioned, and we give notice before adding to it.
| Sub-processor | Purpose | Data it can reach | Location | Their certifications |
|---|---|---|---|---|
| [HOSTING PROVIDER] | Application hosting, database, storage | All customer data at rest | [REGION] | [THEIR CERTIFICATIONS] |
| [EMAIL DELIVERY] | Transactional and notification email | Recipient addresses, message content | [REGION] | [THEIR CERTIFICATIONS] |
| Sentry | Application error reporting | Technical detail of a failure, which may include the page and the account making the request | [REGION] | [THEIR CERTIFICATIONS] |
| [PAYMENT PROVIDERS] | Payment processing | Billing contact and payment details. See Payments and PCI DSS | [REGION] | PCI DSS |
| [SUPPORT TOOLING] | Support ticketing and correspondence | Whatever a customer includes in a ticket | [REGION] | [THEIR CERTIFICATIONS] |
The maintained list lives at [SUB-PROCESSOR LIST URL]. We give [NOTICE PERIOD] days’ notice before a new sub-processor begins handling customer data, and you can subscribe to those notices at [SUBSCRIBE URL]. The list is referenced by URL from our Data Processing Addendum rather than reproduced inside it, so it can change without either party re-executing an agreement.
Data residency and international transfers
Customer data is stored in [PRIMARY REGION], with backups held in [BACKUP REGION]. Where that involves moving personal data out of the EEA or the UK, the transfer needs a lawful basis, and the basis we rely on is set out below.
| Transfer | Mechanism | Supporting assessment | Last confirmed |
|---|---|---|---|
| EEA to [REGION] | Standard Contractual Clauses, module [N] | Transfer Impact Assessment | [DATE] |
| UK to [REGION] | The UK International Data Transfer Addendum | As above | [DATE] |
EU data residency is [EU RESIDENCY POSITION]. It is worth being clear that this is an infrastructure commitment rather than a legal one: it is not a clause we can write, it is a region we have to run in. For some buyers it is decisive, and if it is decisive for you, tell us early rather than late.
Why this section carries dates and the others do not
Transfer law has moved repeatedly, through court decisions and successive replacement frameworks, and each move has invalidated arrangements that were correct the day before. It is the one part of this page that can become wrong without anything at SorviAI changing and without anybody here noticing.
So the mechanism rows carry the date they were last confirmed with counsel, rather than an implied “as at publication”. If a date above is more than a year old, treat it as a question to ask us rather than an answer.
Our security architecture
Full detail is on the Security page. The summary here exists because a reviewer arriving at a compliance page holding no certificates deserves to know, in one screen, what is actually running.
Tenant isolation. Every SorviAI customer is provisioned with a dedicated PostgreSQL schema. Customer records are held in separate database schemas rather than in shared tables partitioned by an identifier column, which removes an entire class of cross-tenant query error rather than relying on every query being written correctly. Requests are resolved to a tenant before reaching application code, authentication tokens are scoped to a single tenant and validated on every request, and the data access layer applies schema-aware filtering automatically. A token issued for one workspace cannot read another.
Authentication and authorisation. Access tokens expire after 60 minutes and are renewed through a refresh flow while you are active. Within a workspace, access is governed by role-based permissions scoped to each application, so a role granted in Finance conveys no access to Inventory. Administrative rights are tiered rather than binary: workspace administrators manage the whole workspace, application administrators manage only their own application, and everything else is granted per permission against a central registry.
Audit logging. Audit records are written to the tenant’s own schema, so the audit trail is isolated on the same boundary as the data it describes.
The gaps are on the Security page too
Multi-factor authentication, audit log retention periods, the layer at which encryption at rest is applied, backup restore testing, documented recovery targets and external penetration testing are all stated there as open, with whatever roadmap date applies, rather than left out.
This is not modesty. A reviewer assumes the worst about an omission and then asks anyway, so the round trip happens either way and the only variable is whether it costs you a week. You will find our gaps faster on our own page than in a questionnaire exchange.
Requesting documents
Everything marked public in What we provide instead needs no request at all. For the rest, one address reaches us and we answer in English.
- Tell us three things. Your organisation, the framework or control set your policy actually names, and your deadline. The third one matters more than people expect: it changes what we prioritise, and we would rather tell you early that we cannot meet it.
- We answer your questionnaire, on your form. We have no policy of responding only to a form of our own, and we do not charge for completing one. If your form asks about a control we do not have, the answer will say so.
- Anything under NDA needs a mutual NDA in place first. Today that applies to nothing, because the documents it would cover do not yet exist. Once a SOC 2 report or a penetration test summary exists, this is the route to it.
Requests reach [COMPLIANCE CONTACT EMAIL], and we aim to respond within [N] business days.
How to contact us
One address for security questionnaires, document requests, and anything on this page you think is wrong. We would rather hear about it than not.
Compliance and vendor review
Data protection contacts
Some of the regimes in Regulations we comply with require a named contact inside the region. Where one is required of us, it is listed here.
The regulators
If you are not satisfied with our answer on a data protection matter, you can go to the supervisory authority for your region. We would rather you came to us first, but nothing here requires you to.
Key terms
The words on this page that carry a specific meaning, in plain language. Several of them are used loosely in vendor marketing, which is the reason they are here.
Certification
A formal statement by an accredited body that an organisation meets a published standard, backed by a certificate with a number and an expiry date. ISO 27001 works this way. The important property is that the body issuing it is accredited by someone else in turn, so the certificate is not simply the auditor’s opinion of itself.
It always expires. A certification is a statement about a period, never a permanent property of a company.
Attestation
A report in which an auditor states an opinion on management’s description of its own controls. SOC 2 works this way. Nobody is “SOC 2 certified” in the strict sense, because no certificate is issued; what exists is a report, with an opinion, covering a stated period and a stated scope.
The distinction matters when reading a vendor’s claim, because an attestation’s value depends entirely on its scope and period, both of which are easy to leave out.
Information security management system
The ISO 27001 term for running security as a defined system rather than as a set of individual good decisions: a documented risk assessment method, a selected set of controls with reasons, internal audits, and management review on a schedule.
The certificate attests that the system exists and operates. It deliberately says nothing about whether any particular control is well engineered, which is why an ISO 27001 certificate and a technical security review answer different questions.
Type I and Type II
Two forms a SOC report can take. Type I asks whether controls were designed appropriately, as at one date. Type II asks whether they actually operated effectively across a window, typically six to twelve months, and involves the auditor sampling evidence from throughout that window.
Type II is the one enterprise buyers mean. The difference is not a detail: a Type I report can be obtained by a company whose controls have never once run.
Trust services criteria
The five areas a SOC 2 report can cover: security, availability, processing integrity, confidentiality and privacy. Only security is mandatory, and the other four are chosen scope.
Two vendors can both hold “SOC 2 Type II” while one covers security alone and the other covers all five. If availability matters to you, the framework name does not tell you whether it was examined; the scope statement in the report does.
Bridge letter
A short letter from a vendor covering the gap between the end of the period a SOC report examined and today, stating that no material change to the controls has occurred in the interval.
Reviewers ask for one because a report issued for a window ending nine months ago says nothing about the intervening nine months. It is signed by the vendor rather than the auditor, so it is a representation, not an audited finding.
Sub-processor
A third party we engage that can access customer personal data in the course of providing our service: hosting, email delivery, error tracking, payment processing, support tooling. Your contract is with us, and our contract with them has to pass down equivalent obligations.
The reason the list is published rather than supplied on request is that data protection law generally gives a customer the right to object to a new one, and that right is meaningless without advance notice.
Standard Contractual Clauses
Pre-approved contract terms published by the European Commission that provide a lawful basis for moving personal data out of the EEA to a country without an adequacy decision. The UK has its own equivalent addendum.
They come in modules for different relationships, such as controller to processor. Citing “SCCs” without the module is the same species of imprecision as citing “SOC 2” without the type.
Transfer Impact Assessment
A documented assessment of whether the law in the destination country would undermine the protections the Standard Contractual Clauses promise, chiefly by giving public authorities access to the data. It is required alongside the clauses, not instead of them.
It is the part most often skipped, and it is the part that has repeatedly been the subject of the court decisions that changed the rules.
Controller and processor
Two roles defined by data protection law. The controller decides why and how personal information is used. The processor handles it only on the controller’s documented instructions.
For the business records in your workspace you are the controller and SorviAI is the processor, so we may not decide to use that data for our own purposes. For your own account with us, and for our marketing list, SorviAI is the controller. Both are true at once, and our GDPR page sets out which applies where.
Vendor security questionnaire
The form a buyer’s security or risk team sends a prospective vendor, often several hundred questions long, covering isolation, encryption, access control, logging, backups, incident response and sub-processors.
A certification exists in large part to pre-answer it. Where a vendor holds none, as here, the questionnaire is answered directly, which is slower for both sides and is the practical cost of being pre-certification.
Data residency
A commitment that data is physically stored in a particular country or region, and stays there. Distinct from a transfer mechanism, which makes a cross-border transfer lawful rather than preventing it.
Residency is an infrastructure commitment: it means running in a region, with the cost and operational consequences that follow. No clause in an agreement can substitute for it, which is why Data residency and international transfers treats it as a separate question.