Compliance
Where Veridenti stands on the frameworks enterprises ask about. We state this plainly and don't overclaim.
Current status
| Framework | Status |
|---|---|
| SOC 2 | Readiness in progress (Type I targeted first) |
| ISO 27001 | Planned (on roadmap) |
| GDPR / CCPA | Aligned data handling; DPA available at contracting (counsel-approved) |
| HIPAA | Zero-knowledge architecture; BAA in preparation |
| 21 CFR Part 11 / Annex 11 | Supported via the tamper-evident, hash-chained audit log |
Data residency & sovereignty
Encrypted vault data can be pinned to a region (fail-closed). For strict sovereign regimes, Veridenti can target a sovereign provider, and the zero-knowledge design means a foreign legal request yields only undecryptable ciphertext. See Data residency.
Audit evidence
The tamper-evident audit log and Access reviews produce the recertification and activity evidence auditors expect, exportable on demand.
NoteFor your current certification status, a DPA, or a security questionnaire, contact your account team — we'll turn these around quickly.
What if…
- We need a signed BAA today — talk to your account team; a BAA is in preparation and availability depends on your plan and use case.
- Our auditor needs a SOC 2 report — request our current status and timeline; we share what's available under NDA.
Was this helpful?