// Trust Centre

Security & Compliance Roadmap

Current certification status, what exists today, and the sequenced path to SOC 2 Type I.

Version 1.0 · Last reviewed: 2026-07-24
Download PDF

Current State

No certifications held today. No SOC 2 (Type I or II), no ISO 27001, no external penetration test performed, no external auditor engaged.

What Exists Today

  • A self-authored SOC 2 readiness assessment mapped to the Trust Services Criteria, with gaps explicitly marked
  • Nine adopted security policies (adopted 24 July 2026), plus a SOC 2 program plan and a vendor register
  • Append-only security-event and audit-event streams
  • Access-review evidence export
  • Database-enforced row-level security across the schema
  • AES-256-GCM credential encryption
  • Dual-control approvals

Milestones

SOC 2 Type I target

July 2027.

External penetration test

July 2027, alongside SOC 2 preparation.

Restore hosted CI as the enforced merge gate

Near-term roadmap item; no date committed.

Enable scheduled database backups

Standing remediation item — the production database tier currently includes no scheduled backups (verified 24 July 2026). No date committed.

Formal policy adoption

Done — the nine-policy pack was adopted on 24 July 2026.

Professional indemnity insurance

Not yet bound; no date committed.

Incident-response formalisation is tied to SOC 2 preparation — closing the gap flagged in the readiness assessment.

Incident-response formalisation target date

Alongside SOC 2 preparation; target July 2027.

Framing

Certification work is deliberately sequenced after first design-partner commitments; the readiness map exists so the gap between today and Type I is known and bounded.