Compliance
A continuous compliance program, not a one-time checkbox
We treat compliance as an ongoing engineering discipline - and we do not claim certifications we have not earned. Here is exactly where each framework stands.
Frameworks
Where we stand
| Framework | Status | Notes |
|---|---|---|
| GDPR | Aligned | Data minimisation, deletion within 90 days, user rights honoured. |
| CCPA / CPRA | Aligned | No sale of personal data; access and deletion on request. |
| SOC 2 Type II | Planned | Audit planned as the company grows out of beta. |
| ISO 27001 | Planned | Controls designed with certification in mind. |
| PCI DSS | N/A by design | Card data handled entirely by our payment provider (Stripe). |
| HIPAA | Not offered | SystemFlow is not intended for PHI workloads today. |
Data residency
Where your data lives
SystemFlow runs on a single region today. Per-region data pinning and self-hosting are on the roadmap, not available yet - tell us if that's a requirement and we'll factor it into the timeline.
Subprocessors
Who we work with
Database and auth run on Supabase, billing runs through Stripe, the AI reviewer calls Anthropic's API, and transactional email goes through our SMTP provider. We'll notify customers in advance of any material change to this list.
Need a DPA or audit report?
Request documentation through the Trust Center or talk to our compliance team.